PT-2026-94395 · Unknown · Async Http Client
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AsyncHttpClient versions 2.0.0 through 2.16.0
AsyncHttpClient versions 3.0.0 through 3.0.11
Description
When using an HTTP proxy to reach an HTTPS origin, the library may expose preemptive origin credentials. This occurs because
NettyRequestFactory and the sendRequestWithNewChannel function in NettyRequestSender attach the Authorization header to the plaintext CONNECT request before the TLS tunnel is established. Consequently, Basic or Digest credentials, as well as per-connection NTLM, Kerberos, or SPNEGO tokens intended for the origin, are transmitted in cleartext and are visible to the proxy and any observers on the network hop between the client and the proxy.Recommendations
Update to version 2.16.1 or later.
Update to version 3.0.12 or later.
As a temporary workaround, avoid using preemptive origin authentication when using an HTTP proxy, or connect to the origin without using a CONNECT proxy.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Async Http Client