http4k-security-digest is vulnerable to Authentication Bypass by Capture-replay
81
High Risk
DigestAuthProvider.verify in the http4k Digest authentication provider does not check the uri parameter of the client's Authorization: Digest response against the actual request URL. A captured Digest response can be replayed against any other URL served by the same realm, breaking the per-request-URL binding the Digest scheme relies on. This lets a previously observed authentication be reused to reach a different protected resource without valid credentials for that URL. The fix rejects credentials whose uri parameter does not match the request URL.
You are affected if you are using a version that falls within the vulnerable range and you use http4k-security-digest for HTTP Digest authentication.
http4k-security-digest is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.1 - 4.50.0.0, 5.0.0.0 - 5.41.0.0 and 6.0.0.0 - 6.49.0.0.
Upgrade the org.http4k:http4k-security-digest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant