The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Reactor_netty | Pivotal | 0.8.0 (including) | 0.8.15 (including) |
Reactor_netty | Pivotal | 0.9.0 (including) | 0.9.4 (including) |
Text-Only RHOAR | RedHat | reactor-netty | * |