CyberRota Analysis
AI-GeneratedEclipse Vert.x versions up to 4.5.29 and 5.1.4 are vulnerable due to the DefaultRedirectHandler improperly propagating all request headers during cross-origin HTTP 30x redirects, exposing sensitive information such as Authorization and Cookie headers to potentially malicious redirect targets. This vulnerability allows attackers to capture credentials and tokens if they can manipulate the redirect URL. Organizations using affected versions of Vert.x should prioritize patching to mitigate the risk of credential leakage.
Original NVD Description
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. As a result, credential headers, including Authorization, Cookie, Proxy-Authorization, and arbitrary custom headers such as X-API-Token, are forwarded to the redirect destination without the caller's knowledge. An attacker who can cause a Vert.x HttpClient to issue a request that is redirected to an attacker-controlled host (for example, by supplying a URL to a webhook dispatcher, image proxy, or microservice URL fetcher) can capture bearer tokens, basic-auth credentials, session cookies, and API keys attached to the original request.
Related CVEs
Other vulnerabilities affecting the same vendor(s)