Security Advisory

CVE-2019-11284

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-10-17 17:40:12
Last updated 2024-09-16 23:36:09
Assigner pivotal
CVSS score 6.8
State PUBLISHED

Description

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.