In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.asynchttpclient:async-http-client to version 3.0.14 or higher.
org.asynchttpclient:async-http-client is a maven plugin for the Async Http Client (AHC) classes.
Affected versions of this package are vulnerable to Protection Mechanism Failure due to improper handling of the scheme when processing Set-Cookie headers. An attacker can overwrite, plant, or delete secure cookies by sending crafted HTTP responses over plaintext connections, which can result in session fixation, CSRF token manipulation, or removal of critical cookies. This is only exploitable if a plaintext host under the same site is able to set cookies for the target domain.
This vulnerability can be mitigated by not sharing one CookieStore between plaintext and HTTPS origins that are not mutually trusted, or by disabling the cookie store.