Hear from the Spring team this January at SpringOne. >

CVE-2022-31684: Reactor Netty HTTP Server may log request headers

The Reactor Netty 1.0.24 release on October 11 included fix for CVE-2022-31684 affecting Reactor Netty HTTP Server.
Users are encouraged to update as soon as possible.

Reactor Netty is used internally in many frameworks including Spring WebFlux and its WebClient.
If you have a Spring Boot application, you can upgrade to Reactor BOM 2020.0.24.

comments powered by Disqus