Description
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1019 | The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects. |
Github GHSA |
GHSA-gpch-h32j-gx6x | Insufficiently Protected Credentials in Reactor Netty |
References
History
Fri, 04 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom reactor Netty |
|
| CPEs | cpe:2.3:a:broadcom:reactor_netty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pivotal
Pivotal reactor Netty |
Broadcom
Broadcom reactor Netty |
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-17T01:02:01.211Z
Reserved: 2020-01-03T00:00:00.000Z
Link: CVE-2020-5404
No data.
Status : Modified
Published: 2020-03-03T18:15:12.157
Modified: 2026-09-04T18:59:12.370
Link: CVE-2020-5404
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-522
Insufficiently Protected Credentials
EUVD
Github GHSA