Impact
AsyncHttpClient’s cookie store silently overrides a caller‑supplied Cookie header when the store contributes a cookie for the same origin. This behavior causes a request that explicitly sets a cookie to be executed with a different cookie, resulting in the request running under an unintended session. The underlying weakness is a lack of proper authorization checks on cookie handling, identified as CWE-287.
Affected Systems
AsyncHttpClient (async-http-client) versions 2.1.0 through 3.0.14 inclusive are affected. Applications that use a shared client instance with the default cookie store can experience the cookie override. The problem is resolved in version 3.0.14.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is through client code that sets a Cookie header while a shared client maintains a cookie store; a malicious user can inject a cookie into the store to hijack another user’s session. This inference is based on the description provided, which specifies the mechanism of the override and the resulting session hijacking risk.
OpenCVE Enrichment