PT-2024-39485 · Eclipse · Eclipse Dataspace Components

Marta Rybczynska

·

Published

2024-09-27

·

Updated

2025-01-09

·

CVE-2024-9202

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions Eclipse Dataspace Components versions 0.1.3 through 0.9.0
Description The issue concerns the Connector component in Eclipse Dataspace Components, which is responsible for filtering datasets that another party can see in a requested catalog. However, there is a possibility to request a single dataset without the correct filtering, potentially allowing parties to see datasets they should not have access to and exposing sensitive information. Exploiting this issue requires knowing the ID of a restricted dataset, but some IDs may be guessed through automated attempts.
Recommendations For Eclipse Dataspace Components versions 0.1.3 through 0.9.0, patch immediately to mitigate risks. As a temporary workaround, consider restricting access to the DatasetResolverImpl function until a patch is available. Avoid using the affected code in the DatasetResolverImpl function, specifically lines 76-79, until the issue is resolved.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-9202

Affected Products

Eclipse Dataspace Components