Vulnerabilities (CVE)

Filtered by vendor Pivotal Subscribe
Filtered by product Reactor Netty
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5404 1 Pivotal 1 Reactor Netty 2021-07-07 4.9 MEDIUM 5.9 MEDIUM
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.