Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. As a result, credential headers, including Authorization, Cookie, Proxy-Authorization, and arbitrary custom headers such as X-API-Token, are forwarded to the redirect destination without the caller's knowledge. An attacker who can cause a Vert.x HttpClient to issue a request that is redirected to an attacker-controlled host (for example, by supplying a URL to a webhook dispatcher, image proxy, or microservice URL fetcher) can capture bearer tokens, basic-auth credentials, session cookies, and API keys attached to the original request.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
信息暴露
Vulnerability Title
Eclipse vert.x 信息泄露漏洞
Vulnerability Description
Eclipse vert.x是美国Eclipse基金会开源的一个反应式应用开发框架。 Eclipse vert.x 4.5.29及之前版本和5.1.4及之前版本存在安全漏洞,该漏洞源于DefaultRedirectHandler (vertx-core)在跨域HTTP 30x重定向时传播所有请求标头,仅剥离Content-Length,未进行源比较,导致凭证标头(包括Authorization、Cookie、Proxy-Authorization及自定义标头)被转发到重定向目标,可能使攻击者捕获原始请求中
CVSS Information
N/A
Vulnerability Type
N/A