Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
History

Fri, 09 May 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-532
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2022-10-19T00:00:00.000Z

Updated: 2025-05-09T14:29:04.873Z

Reserved: 2022-05-25T00:00:00.000Z

Link: CVE-2022-31684

cve-icon Vulnrichment

Updated: 2024-08-03T07:26:01.025Z

cve-icon NVD

Status : Modified

Published: 2022-10-19T22:15:10.237

Modified: 2025-05-09T15:15:53.317

Link: CVE-2022-31684

cve-icon Redhat

Severity : Low

Publid Date: 2022-10-20T00:00:00Z

Links: CVE-2022-31684 - Bugzilla