Impact
The vulnerability occurs in the AsyncHttpClient library, where SCRAM and Digest authentication responses are not properly verified. When the SCRAM ServerSignature or Digest rspauth verification matches a logged mismatch, the library still delivers the response as authenticated. This results in a form of authentication bypass, allowing an attacker to impersonate a server without knowledge of the shared secret. The weakness is represented by CWE‑287 (Improper Authentication), CWE‑347 (Improper Verification for Mutual Authentication), and CWE‑390 (Check for Error Conditions without Action).
Affected Systems
Affected products are Java applications that use AsyncHttpClient versions 3.0.8 through 3.0.12. The issue is present in all Java projects incorporating this library within that version range. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 3.7 reflects a low‑to‑moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation as of the current data. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw if an application relies on non‑TLS or compromised transport layers, enabling impersonation of the server. The problem manifests only when SCRAM or Digest authentication is activated; consequently, the attack vector requires an application using these authentication methods on insecure connections.
OpenCVE Enrichment
Github GHSA