Description
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0705 | Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to. |
Github GHSA |
GHSA-j52r-xc68-q8f4 | Insufficiently Protected Credentials in Pivotal Reactor Netty |
References
| Link | Providers |
|---|---|
| https://pivotal.io/security/cve-2019-11284 |
|
History
Fri, 04 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom reactor Netty |
|
| CPEs | cpe:2.3:a:broadcom:reactor_netty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pivotal
Pivotal reactor Netty |
Broadcom
Broadcom reactor Netty |
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-16T23:36:09.978Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11284
No data.
Status : Modified
Published: 2019-10-17T18:15:12.110
Modified: 2026-09-04T18:59:12.370
Link: CVE-2019-11284
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA