Description
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Remediation
References
https://pivotal.io/security/cve-2019-11284
Related Vulnerabilities
CVE-2020-2169 Vulnerability in maven package org.jenkins-ci.plugins:queue-cleanup
CVE-2023-25141 Vulnerability in maven package org.apache.sling:org.apache.sling.jcr.base
CVE-2023-32314 Vulnerability in npm package vm2
CVE-2023-31103 Vulnerability in maven package org.apache.inlong:manager-test
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-debug-jdk14