CVE-2019-11284: Reactor Netty authentication leak in redirects
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11284?
CVE-2019-11284 is a vulnerability in Pivotal Reactor Netty versions prior to 0.8.11 that allows a remote unauthenticated malicious user to gain access to credentials for a different server.
How does CVE-2019-11284 affect Pivotal Reactor Netty?
CVE-2019-11284 affects Pivotal Reactor Netty versions prior to 0.8.11 by passing headers, including authorization ones, through redirects.
What is the severity of CVE-2019-11284?
The severity of CVE-2019-11284 is high with a CVSS score of 8.6.
How can a remote malicious user exploit CVE-2019-11284?
A remote unauthenticated malicious user can exploit CVE-2019-11284 by redirecting headers, including authorization ones, and gaining access to credentials for a different server.
What is the recommended solution to fix CVE-2019-11284?
To fix CVE-2019-11284, it is recommended to upgrade Pivotal Reactor Netty to version 0.8.11 or later.