5.9
CVSSv3

CVE-2020-5404

Published: 03/03/2020 Updated: 07/07/2021
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.9 | Impact Score: 4.2 | Exploitability Score: 1.6
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

The HttpClient from Reactor Netty, versions 0.9.x before 0.9.5, and versions 0.8.x before 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal reactor netty

Vendor Advisories

Synopsis Moderate: Red Hat support for Spring Boot 272 update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Application Runtimes Description Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths an ...