PT-2019-12230 · Pivotal · Pivotal Reactor Netty
Published
2019-10-17
·
Updated
2019-10-23
·
CVE-2019-11284
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pivotal Reactor Netty versions prior to 0.8.11
Description
The issue allows a remote unauthenticated malicious user to potentially gain access to credentials for a different server than they have access to, by passing headers through redirects, including authorization ones.
Recommendations
For versions prior to 0.8.11, update to version 0.8.11 or later to resolve the issue.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pivotal Reactor Netty