6.5
CVE-2020-5404
- EPSS 0.23%
- Veröffentlicht 03.03.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:04
- Quelle security@pivotal.io
- CVE-Watchlists
- Unerledigt
Authentication Leak On Redirect With Reactor Netty HttpClient
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pivotal ≫ Reactor Netty Version >= 0.8.0 <= 0.8.15
Pivotal ≫ Reactor Netty Version >= 0.9.0 <= 0.9.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.455 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 1.6 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
|
| nvd@nist.gov | 4.9 | 6.8 | 4.9 |
AV:N/AC:M/Au:S/C:P/I:P/A:N
|
| security@pivotal.io | 6.5 | 1.3 | 4.7 |
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.