async-http-client is vulnerable to Cleartext Transmission of Sensitive Information
75
High Risk
When a SOCKS proxy is configured with proxy authentication, the client does not check the proxy type, so it attaches the SOCKS proxy's Proxy-Authorization header, or answers a 407 challenge, on a connection that reaches the origin server through the SOCKS tunnel rather than the proxy. The origin server, and anyone on the origin side of the wire, receives the proxy's own credentials, which are directly reversible for Basic and can be replayed or cracked offline for NTLM, Kerberos, and SPNEGO. This is reachable with preemptive proxy authentication and, by default, whenever a hostile origin answers with 407. The fix attaches proxy credentials only to a request the proxy itself receives and stops answering a 407 on a non-HTTP proxy connection with the proxy's credentials.
You are affected if you are using a version that falls within the vulnerable range and you configure proxy authentication on a SOCKS proxy.
async-http-client is vulnerable to Cleartext Transmission of Sensitive Information in versions 2.1.0 - 2.16.0 and 3.0.0 - 3.0.11.
Upgrade the async-http-client library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.