Loading
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
Use CWE-522, Pivotal vendor hub and Reactor Netty product page to widen CVE-2020-5404 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-11284, CVE-2023-34062 and CVE-2020-5403 for nearby disclosures in the same product family.