#VU101805 Resource management error in Async-http-client - CVE-2024-53990
Published: December 16, 2024
Async-http-client
Asynchttpclient Project
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of cookies stored in the self-managed CookieStore, also know as cookie jar. The application silently replaces values of previously set cookies with new ones used by different requests. A remote attacker can gain access to information stored in cookies.
Remediation
External links
- https://github.com/AsyncHttpClient/async-http-client/commit/d5a83362f7aed81b93ebca559746ac9be0f95425
- https://github.com/AsyncHttpClient/async-http-client/issues/1964
- https://github.com/AsyncHttpClient/async-http-client/pull/2033
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj5-cf8g-g2fv