{"id":"GHSA-mfj5-cf8g-g2fv","summary":"AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s","details":"### Summary\n\nWhen making any HTTP request, the automatically enabled and self-managed `CookieStore` (aka cookie jar) will silently replace explicitly defined `Cookie`s with any that have the same name from the cookie jar. For services that operate with multiple users, this can result in one user's `Cookie` being used for another user's requests.\n\n### Details\n\nThis issue is described without security warnings here:\n\nhttps://github.com/AsyncHttpClient/async-http-client/issues/1964\n\nA PR to fix this issue has been made:\n\nhttps://github.com/AsyncHttpClient/async-http-client/pull/2033\n\n### PoC\n\n1. Add an auth `Cookie` to the `CookieStore`\n    - This is identical to receiving an HTTP response that uses `Set-Cookie`, as shown in issue #1964 above.\n2. Handle a different user's request where the same `Cookie` is provided as a passthrough, like a JWT, and attempt to use it by explicitly providing it.\n3. Observe that the user's cookie in step 2 is passed as the Cookie in step 1.\n\n### Impact\n\nThis is generally going to be a problem for developers of backend services that implement third party auth features and use other features like token refresh. The moment a third party service responds by _setting_ a cookie in the response, the `CookieStore` will effectively break almost every follow-up request (hopefully by being rejected, but possibly by revealing a different user's information).\n\nIf your service sets cookies based on the response that happens here, it's possible to lead to even greater levels of exposure.\n\n### Workaroud\n\nYou can avoid this issue by disabling the `CookieStore` during client creation:\n\n```java\nDefaultAsyncHttpClientConfig.Builder clientBuilder = Dsl.config()\n .setCookieStore(null)\n // other configuration\n ;\n```","aliases":["CVE-2024-53990"],"modified":"2026-09-10T03:50:21.642131422Z","published":"2024-12-02T20:04:43Z","database_specific":{"cwe_ids":["CWE-287"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-12-02T20:04:43Z","nvd_published_at":"2024-12-02T18:15:11Z"},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj5-cf8g-g2fv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53990"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/issues/1964"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/pull/2033"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/d5a83362f7aed81b93ebca559746ac9be0f95425"},{"type":"PACKAGE","url":"https://github.com/AsyncHttpClient/async-http-client"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/blob/main/CHANGES.md#from-20-to-21"}],"affected":[{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.12.4"}]}],"versions":["2.1.0","2.1.1","2.1.2","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.11.0","2.12.0","2.12.1","2.12.2","2.12.3","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.7.0","2.8.0","2.8.1","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-mfj5-cf8g-g2fv/GHSA-mfj5-cf8g-g2fv.json"}},{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0.Beta1"},{"fixed":"3.0.1"}]}],"versions":["3.0.0","3.0.0.Beta1","3.0.0.Beta2","3.0.0.Beta3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-mfj5-cf8g-g2fv/GHSA-mfj5-cf8g-g2fv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}