CVE-2019-11284
Executive Summary
Pivotal Reactor Netty (v<0.8.11) incorrectly forwards all HTTP headers, including Authorization, during redirects. An unauthenticated attacker can trigger a redirect to a target server and capture credentials intended for that server, enabling unauthorized access to resources on a different domain. This flaw exposes sensitive authentication data across domains without user interaction.
Authoritative CVE Metadata - CVSS Base Score: 8.6 (HIGH) - Published: 2019-10-17T18:15:12.110 - Last Modified: 2026-09-04T18:59:12.370
Original Description: Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
"No one has ever become poor by giving."
— Anne Frank