Resource management error in Async-http-client - CVE-2024-53990
Published: December 16, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of cookies stored in the self-managed CookieStore, also know as cookie jar. The application silently replaces values of previously set cookies with new ones used by different requests. A remote attacker can gain access to information stored in cookies.
Affected software
watsonx.data
Rational Performance Tester
DevOps Test Performance
Red Hat Camel for Spring Boot
How to mitigate CVE-2024-53990
watsonx.data - update to 2.1.1
DevOps Test Performance - update to 11.0.7
Red Hat Camel for Spring Boot - update to 4.8.3
External References
- https://github.com/AsyncHttpClient/async-http-client/commit/d5a83362f7aed81b93ebca559746ac9be0f95425
- https://github.com/AsyncHttpClient/async-http-client/issues/1964
- https://github.com/AsyncHttpClient/async-http-client/pull/2033
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj5-cf8g-g2fv