Description
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Remediation
References
https://pivotal.io/security/cve-2019-11284
Related Vulnerabilities
CVE-2018-1000110 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2014-7816 Vulnerability in maven package io.undertow:undertow-core
CVE-2020-2229 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-1698 Vulnerability in maven package org.keycloak:keycloak-authz-client
CVE-2021-36372 Vulnerability in maven package org.apache.ozone:ozone-common