Reactor Netty HttpClient Can Leak Credentials on Cross-Domain Redirects (CVE-2020-5404)
·
CVE-2020-5404 affects Reactor Netty's HttpClient in versions 0.9.x before 0.9.5 and 0.8.x before 0.8.16, where credentials may be leaked during a redirect to a different domain, but only when the client is explicitly configured to follow redirects. The issue is part of a broader set of Reactor Netty advisories that also includes the HttpServer flaws CVE-2020-5403, CVE-2022-31684, CVE-2023-34062 (directory traversal) and CVE-2023-34054 (denial of service).