Impact
The AsyncHttpClient library performs incomplete validation of cookie Domain attributes from versions 2.16.0 to 3.0.14, allowing cookies set by one origin to be stored and later sent to another origin, especially on public-suffix and IP-address hosts. This flaw can be exploited to inject session cookies or other credential-bearing data, potentially enabling session fixation attacks against Java applications that share a single HTTP client across trust boundaries. The vulnerability is categorized as a partial origin check failure (CWE-1275) and an incomplete input validation issue (CWE-384).
Affected Systems
AsyncHttpClient library, used in Java applications for asynchronous HTTP requests, is affected for releases ranging from 2.16.0 through 3.0.14. Applications that incorporate any of these versions and rely on the default ThreadSafeCookieStore are susceptible; the flaw is patched in 3.0.14 and later releases.
Risk and Exploitability
The CVSS score of 4.0 represents a moderate severity risk. Although no EPSS score is available and the vulnerability is not listed in KEV, the attack vector is feasible for applications that share a single client instance across different trust domains; an attacker controlling a source origin can inject a cookie that will be treated as belonging to a target domain. Remediation through an update mitigates the risk effectively, while failure to patch leaves systems exposed to cookie theft and possible session fixation.
OpenCVE Enrichment