Impact
The AsyncHttpClient library misinterprets a Digest authentication challenge that lacks a usable nonce as a Basic challenge, causing the client to send the username and password in plain text. This flaw allows an attacker to capture credentials that were intended to remain confidential, representing a cleartext transmission vulnerability. The issue is rooted in improper handling of authentication semantics and is classified under CWE‑319, CWE‑522, and CWE‑757.
Affected Systems
Java applications that incorporate the AsyncHttpClient library before version 3.0.13 or 2.16.1 are affected. The vulnerability applies to both the standard and proxy-enabled implementations of the client, meaning any upstream or intermediary proxy that can alter the Digest challenge will trigger the flaw.
Risk and Exploitability
With a CVSS score of 8.7, this vulnerability is considered high severity. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it may not have widespread public exploitation yet. A malicious origin or proxy that can inject a Digest challenge without a nonce can coerce the client into sending Basic authentication credentials. Exploitation requires the attacker to influence the client’s authentication flow, which is feasible through network manipulation or compromised network elements. The impact could be significant if the attacker gains access to user credentials used by the application.
OpenCVE Enrichment