{"id":"CVE-2019-11284","title":"Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones","summary":"Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-522","CWE-522"],"vendor":"broadcom","product":"reactor_netty","affected":["reactor_netty >= 0.8.0, < 0.8.11"],"patched":["reactor_netty 0.8.11"],"published":"2019-10-17","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-11284","references":[{"url":"https://pivotal.io/security/cve-2019-11284","label":"security@pivotal.io"},{"url":"https://pivotal.io/security/cve-2019-11284","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00894,"epssPercentile":0.57475,"ingestedAt":"2026-09-04T19:26:35.122Z","slug":"CVE-2019-11284","body":"## Overview\n\nPivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.\n\n## Affected\n\n- `reactor_netty >= 0.8.0, < 0.8.11`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `reactor_netty 0.8.11`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}