Description
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Remediation
References
https://pivotal.io/security/cve-2019-11284
Related Vulnerabilities
CVE-2022-34792 Vulnerability in maven package org.jenkins-ci.plugins:recipe
CVE-2023-24998 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-30543 Vulnerability in npm package @web3-react/walletconnect
CVE-2023-31065 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2016-3092 Vulnerability in maven package commons-fileupload:commons-fileupload