PT-2026-94393 · Unknown · Async Http Client
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AsyncHttpClient versions 2.14.5 through 2.16.0
AsyncHttpClient versions 3.0.9 through 3.0.11
Description
A client configured with a client-wide Realm and redirect following can disclose credentials during a cross-origin redirect. This occurs because the authentication path in the Interceptors falls back to the client configuration after the redirect handling clears the per-exchange realm. If an attacker-controlled target returns a 401 response, the client may send Basic or Digest credentials, or a Negotiate or NTLM token, to that origin. This issue is a residual bypass of previous cross-origin credential-stripping fixes.
Recommendations
Update AsyncHttpClient versions 2.14.5 through 2.16.0 to version 2.16.1.
Update AsyncHttpClient versions 3.0.9 through 3.0.11 to version 3.0.12.
Set the Realm on the individual request instead of on the client configuration.
Disable the follow-redirects feature.
Exploit
Fix
Insufficiently Protected Credentials
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Async Http Client