Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
Metrics
Affected Vendors & Products
References
History
Fri, 09 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-532 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-05-09T14:29:04.873Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31684

Updated: 2024-08-03T07:26:01.025Z

Status : Modified
Published: 2022-10-19T22:15:10.237
Modified: 2025-05-09T15:15:53.317
Link: CVE-2022-31684
