Overview
About vulnerability
In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.Details
- Affected product:
- Netty , Spring , azure-sdk-for-java , azure-search-documents , rsocket-java , tika
- Affected packages:
- Spring Integration @ 5.5.19 (+2673 more)