CyberRota Analysis
AI-GeneratedThe Reactor Netty WebSocket client is vulnerable to credential leakage during WebSocket handshake redirects when the HTTP client is configured to follow redirects. This issue affects versions 1.3.0 to 1.3.6, 1.1.0 to 1.2.18, and 1.0.52 and earlier. Organizations utilizing these versions should prioritize patching to mitigate potential exposure of sensitive information.
Original NVD Description
In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)