Lucene search

K
springVioleta GeorgievaSPRING:4476A5A719C3A5E774CC8572DD533037
HistoryOct 20, 2022 - 12:45 p.m.

CVE-2022-31684: Reactor Netty HTTP Server may log request headers

2022-10-2012:45:00
Violeta Georgieva
spring.io
103
reactor netty
http server
logging
vulnerability
spring webflux
webclient
cve-2022-31684
update
spring boot
reactor bom

0.001 Low

EPSS

Percentile

30.4%

The Reactor Netty 1.0.24 release on October 11 included fix for CVE-2022-31684 affecting Reactor Netty HTTP Server.
Users are encouraged to update as soon as possible.

Reactor Netty is used internally in many frameworks including Spring WebFlux and its WebClient.
If you have a Spring Boot application, you can upgrade to Reactor BOM 2020.0.24.

0.001 Low

EPSS

Percentile

30.4%

Related for SPRING:4476A5A719C3A5E774CC8572DD533037