In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.projectreactor.netty:reactor-netty-http(Maven) | 1.3.0-M1 | 1.3.0-M5 | N/A |
| io.projectreactor.netty:reactor-netty-http(Maven) | 0 | 1.2.8 | N/A |
CVSS Metrics