Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.projectreactor.netty:reactor-netty(Maven) | 0 | 0.8.11 | N/A |
CVSS Metrics