PT-2019-12230 · Pivotal · Pivotal Reactor Netty
Publicado
2019-10-17
·
Atualizado
2019-10-23
·
CVE-2019-11284
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pivotal Reactor Netty versions prior to 0.8.11
Description
The issue allows a remote unauthenticated malicious user to potentially gain access to credentials for a different server than they have access to, by passing headers through redirects, including authorization ones.
Recommendations
For versions prior to 0.8.11, update to version 0.8.11 or later to resolve the issue.
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pivotal Reactor Netty