VDB
Sign up
MEDIUM6.8

GHSA-cmxv-58fp-fm3g

AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects

Quick fix

GHSA-cmxv-58fp-fm3g — org.asynchttpclient:async-http-client: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.0.9</version> for org.asynchttpclient:async-http-client

Details

### Impact When redirect following is enabled (followRedirect(true)), AsyncHttpClient forwards Authorization and Proxy-Authorization headers along with Realm credentials to arbitrary redirect targets regardless of domain, scheme, or port changes. This leaks credentials on cross-domain redirects and HTTPS-to-HTTP downgrades.

Additionally, even when stripAuthorizationOnRedirect is set to true, the Realm object containing plaintext credentials is still propagated to the redirect request, causing credential re-generation for Basic and Digest authentication schemes via NettyRequestFactory.

An attacker who controls a redirect target (via open redirect, DNS rebinding, or MITM on HTTP) can capture Bearer tokens, Basic auth credentials, or any other Authorization header value.

### Patches Fixed in version 3.0.9 or 2.14.5. Users should upgrade immediately.

The fix automatically strips Authorization and Proxy-Authorization headers and clears Realm credentials whenever a redirect crosses origin boundaries (different scheme, host, or port) or downgrades from HTTPS to HTTP.

### Workarounds For users unable to upgrade, set (stripAuthorizationOnRedirect(true)) in the client config and avoid using Realm-based authentication with redirect following enabled. Note that (stripAuthorizationOnRedirect(true)) alone is insufficient on versions prior to 3.0.9 or 2.14.5 because the Realm bypass still re-generates credentials.

Alternatively, disable redirect following (followRedirect(false)) and handle redirects manually with origin validation.

### References - Fix commit: https://github.com/AsyncHttpClient/async-http-client/commit/6b2fbb7f8

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.asynchttpclient:async-http-client
Introduced in: 3.0.0.Beta1Fixed in: 3.0.9
Fix# pom.xml: bump <version>3.0.9</version> for org.asynchttpclient:async-http-client
Maven/org.asynchttpclient:async-http-client
Introduced in: 2.0.0Fixed in: 2.14.5
Fix# pom.xml: bump <version>2.14.5</version> for org.asynchttpclient:async-http-client

References