CVE-2020-5404
Authentication Leak On Redirect With Reactor Netty HttpClient
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
El HttpClient del Reactor Netty, versiones 0.9.x anteriores a 0.9.5, y versiones 0.8.x anteriores a 0.8.16, puede ser usado incorrectamente, conllevando a un filtrado de credenciales durante un redireccionamiento hacia un dominio diferente. A fin de que esto ocurra, el HttpClient debe haber sido configurado explícitamente para seguir los redireccionamientos.
Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications for OpenShift as a containerized platform. This release of Red Hat support for Spring Boot 2.7.2 serves as a replacement for Red Hat support for Spring Boot 2.5.12, and includes security, bug fixes and enhancements. For more information, see the release notes listed in the References section. Issues addressed include denial of service and deserialization vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-03 CVE Reserved
- 2020-03-03 CVE Published
- 2024-09-17 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pivotal.io/security/cve-2020-5404 | 2021-07-07 | |
https://access.redhat.com/security/cve/CVE-2020-5404 | 2022-12-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1975160 | 2022-12-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Search vendor "Pivotal" | Reactor Netty Search vendor "Pivotal" for product "Reactor Netty" | >= 0.8.0 <= 0.8.15 Search vendor "Pivotal" for product "Reactor Netty" and version " >= 0.8.0 <= 0.8.15" | - |
Affected
| ||||||
Pivotal Search vendor "Pivotal" | Reactor Netty Search vendor "Pivotal" for product "Reactor Netty" | >= 0.9.0 <= 0.9.4 Search vendor "Pivotal" for product "Reactor Netty" and version " >= 0.9.0 <= 0.9.4" | - |
Affected
|