{"id":"CVE-2020-5404","details":"The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.","aliases":["GHSA-gpch-h32j-gx6x"],"modified":"2026-09-06T14:04:06.582353Z","published":"2020-03-03T18:15:12.157Z","references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2020-5404"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/reactor/reactor-netty","events":[{"introduced":"9194b9cc8552831fbe2af09663b67fd6743d359c"},{"last_affected":"5c9c3df62cfc67afd309e04aa00dab1c33dc0491"},{"introduced":"87fc8e28053ad81075026d168417b711a4dd3055"},{"last_affected":"dc25636204478373d3eec074f3499e76187d72cd"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:broadcom:reactor_netty:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.8.0"},{"last_affected":"0.8.15"},{"introduced":"0.9.0"},{"last_affected":"0.9.4"}]}}],"versions":["v0.9.4.RELEASE","v0.9.3.RELEASE","v0.8.15.RELEASE","v0.9.2.RELEASE","v0.8.14.RELEASE","v0.9.1.RELEASE","v0.8.13.RELEASE","v0.9.0.RELEASE","v0.8.12.RELEASE","v0.8.11.RELEASE","v0.8.10.RELEASE","v0.8.9.RELEASE","v0.8.8.RELEASE","v0.8.7.RELEASE","v0.8.6.RELEASE","v0.8.5.RELEASE","v0.8.4.RELEASE","v0.8.3.RELEASE","v0.8.2.RELEASE","v0.8.1.RELEASE","v0.8.0.RELEASE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5404.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}