Impact
The vulnerability occurs in AsyncHttpClient 3.0.12 when a peer presents a Digest authentication challenge with qop=auth-int. The client computes no expected rspauth value for auth-int, and the framework treats the missing value as unverifiable yet acceptable. As a result, a malicious server that does not know the shared secret can gain authenticated status, effectively spoofing the server for the client. This flaw permits an attacker to pass the mutual‑authentication check and potentially gain unilateral trust of the client, enabling further compromise such as data tampering or denial of service. The weakness aligns with authentication flaws identified in CWEs 303 and 757.
Affected Systems
Any Java application that incorporates AsyncHttpClient version 3.0.12 and uses Digest authentication with qop=auth-int is affected. The issue is resolved in the 3.0.13 release; earlier iterations such as 3.0.12 remain vulnerable.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity authentication bypass. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploit campaigns have been documented to date. Likely exploitation would occur over a network channel where the client initiates a digest challenge to a server; an attacker could provide a forged response to satisfy the client’s validation logic. The attack vector is therefore remote network, with minimal prerequisites beyond an ability to present a response to the client’s digest challenge.
OpenCVE Enrichment