{
  "threat_severity" : "Low",
  "public_date" : "2022-10-20T00:00:00Z",
  "bugzilla" : {
    "description" : "reactor-netty-http: Log request headers in some cases of invalid HTTP requests",
    "id" : "2141353",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2141353"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-117",
  "details" : [ "Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.", "A flaw was found in the Reactor Netty HTTP Server, which may log request headers in some cases of invalid HTTP requests. This could allow an attacker to access privileged information when WARN level logging is enabled." ],
  "affected_release" : [ {
    "product_name" : "Red Hat support for Spring Boot 2.7.13",
    "release_date" : "2023-08-16T00:00:00Z",
    "advisory" : "RHSA-2023:4612",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0",
    "package" : "reactor-netty-http"
  }, {
    "product_name" : "RHINT Camel-Springboot 3.18.3",
    "release_date" : "2022-12-08T00:00:00Z",
    "advisory" : "RHSA-2022:8902",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:3.18.3",
    "package" : "reactor-netty-http"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Quarkus",
    "fix_state" : "Fix deferred",
    "package_name" : "reactor-netty-http",
    "cpe" : "cpe:/a:redhat:quarkus:2"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Fix deferred",
    "package_name" : "reactor-netty-http",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Integration Camel K 1",
    "fix_state" : "Fix deferred",
    "package_name" : "reactor-netty-http",
    "cpe" : "cpe:/a:redhat:integration:1"
  }, {
    "product_name" : "Red Hat Integration Camel Quarkus 1",
    "fix_state" : "Fix deferred",
    "package_name" : "reactor-netty-http",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2"
  }, {
    "product_name" : "Red Hat JBoss Data Grid 7",
    "fix_state" : "Out of support scope",
    "package_name" : "reactor-netty-http",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:7"
  }, {
    "product_name" : "Red Hat OpenShift Application Runtimes",
    "fix_state" : "Fix deferred",
    "package_name" : "reactor-netty-http",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  }, {
    "product_name" : "Red Hat support for Spring Boot",
    "fix_state" : "Affected",
    "package_name" : "reactor-netty-http",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-31684\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-31684" ],
  "name" : "CVE-2022-31684",
  "csaw" : false
}