Reactor Netty是基于 Netty 框架的非阻塞和背压就绪的 TCP/HTTP/UDP/QUIC 客户端和服务器。 Reactor Netty存在安全漏洞,该漏洞源于在链式重定向的某些特定场景中,Reactor Netty HTTP客户端会泄露凭证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VMware | Reactor Netty | 1.0.x< 1.0.49 (Reactor BOM 2020.0.48) |
affected |
1.1.x< 1.1.32 (Reactor BOM 2022.0.27 and 2023.0.20) |
affected | ||
1.2.x< 1.2.8 (Reactor BOM 2024.0.8) |
affected | ||
1.3.x< 1.3.0-M5 (Reactor BOM 2025.0.0-M5) |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware | Reactor Netty | 1.0.x ~ 1.0.49 (Reactor BOM 2020.0.48) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet