Impact
The AsyncHttpClient library creates a connection-pool key based on request parameters but omits the authenticated principal for NTLM and Negotiate authentication, allowing a socket authenticated for one identity to be reused for requests using a different principal and causing the server to execute those subsequent requests as the original identity. This flaw can lead to unauthorized access or actions performed with higher privileges.
Affected Systems
Any Java application that uses AsyncHttpClient versions earlier than 3.0.13 or 2.16.1 and relies on NTLM or Negotiate authentication is vulnerable. Basic or Digest authentication is not affected. Versions 3.0.13 and 2.16.1, and later releases, contain a fix.
Risk and Exploitability
The vulnerability presents a moderate to high risk with a CVSS score of 7.6. Exploitation requires an attacker to influence a client application using the affected library so that it initiates requests under multiple identities. No EPSS data is available, and the flaw is not listed in the CISA KEV catalog, but the authentication bypass could be used to elevate privileges on a target system if the server trusts the authenticated identity. The likely attack vector is remote exploitation via the client application, and no public exploit is known.
OpenCVE Enrichment