Vulnerability Description
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal | Reactor Netty | >= 0.8.0, <= 0.8.15 |
Related Weaknesses (CWE)
References
- https://pivotal.io/security/cve-2020-5404Vendor Advisory
- https://pivotal.io/security/cve-2020-5404Vendor Advisory
FAQ
What is CVE-2020-5404?
CVE-2020-5404 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In...
How severe is CVE-2020-5404?
CVE-2020-5404 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5404?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Reactor Netty.