Description
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7053 | Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens |
Github GHSA |
GHSA-7w4x-4h67-pgmv | Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens |
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 09 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-05-09T14:29:04.873Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31684
Updated: 2024-08-03T07:26:01.025Z
Status : Modified
Published: 2022-10-19T22:15:10.237
Modified: 2025-05-09T15:15:53.317
Link: CVE-2022-31684
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA