GHSA-j52r-xc68-q8f4
GitHub Security Advisory
Insufficiently Protected Credentials in Pivotal Reactor Netty
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Affected Packages
Maven
io.projectreactor.netty:reactor-netty
Affected versions:
0
(fixed in 0.8.11)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 3, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.