Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7053 | Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens |
Github GHSA |
GHSA-7w4x-4h67-pgmv | Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 09 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-05-09T14:29:04.873Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31684
Updated: 2024-08-03T07:26:01.025Z
Status : Modified
Published: 2022-10-19T22:15:10.237
Modified: 2025-05-09T15:15:53.317
Link: CVE-2022-31684
OpenCVE Enrichment
No data.
EUVD
Github GHSA