Lucene search

K
githubGitHub Advisory DatabaseGHSA-7W4X-4H67-PGMV
HistoryOct 20, 2022 - 12:00 p.m.

Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens

2022-10-2012:00:17
CWE-200
GitHub Advisory Database
github.com
30
reactor netty
http server
access tokens
security vulnerability
logging at warn level

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

30.4%

Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may request log headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.

Affected configurations

Vulners
Node
io.projectreactor.netty\reactorMatchnetty

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

30.4%