Impact
The AsyncHttpClient library did not filter cookie domain attributes against the public suffix list before versions 3.0.13 and 2.16.1. An attacker able to make the library send a response containing a Set‑Cookie header for a domain like co.uk could write a cookie that is accepted for any host in that suffix. The shared cookie store would then forward that cookie to unrelated hosts under the same suffix, enabling the attacker to inject or overwrite session‑related cookie values across origins, potentially hijacking user sessions or injecting data manipulated across different services.
Affected Systems
This flaw affects the AsyncHttpClient component of Java applications that depend on the async‑http‑client library, specifically any version earlier than 3.0.13 or 2.16.1. Applications using these legacy versions are vulnerable. The fix is available in 3.0.13 and 2.16.1 releases.
Risk and Exploitability
The reported CVSS score of 6.9 indicates a medium severity, with no EPSS data and the vulnerability not yet listed in KEV. The flaw can be exploited by local code that causes the library to process an adversarial HTTP response; once the cookie is cached, it is automatically appended to subsequent requests, potentially leading to confidentiality and integrity compromise. Because the attack requires building or modifying a Java application using AsyncHttpClient, it is typically a compromise of a deployment or supply‑chain rather than an external network attack. The attack vector is therefore "local code execution via a vulnerable library", and the risk is moderate to high for systems that process sensitive session data across domains.
OpenCVE Enrichment