Description
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Remediation
References
https://pivotal.io/security/cve-2019-11284
Related Vulnerabilities
CVE-2016-3082 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2014-3501 Vulnerability in npm package cordova-android
CVE-2022-37022 Vulnerability in maven package org.apache.geode:geode-core
CVE-2011-0013 Vulnerability in maven package tomcat:catalina
CVE-2018-1190 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-model