PT-2024-7968 · Eclipse · Eclipse Dataspace Components
Marta Rybczynska
·
Published
2024-09-11
·
Updated
2024-09-19
·
CVE-2024-8642
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Dataspace Components versions 0.5.0 through 0.9.0
Description
The issue is related to the ConsumerPullTransferTokenValidationApiController component, which has inadequate authentication procedures. This allows a remote attacker to bypass the token expiration check. The vulnerability requires a dataplane configured to support http proxy consumer pull and includes the module "transfer-data-plane". The affected code was marked deprecated from version 0.6.0 in favor of Dataplane Signaling and was removed in version 0.9.0.
Recommendations
For Eclipse Dataspace Components versions 0.5.0 through 0.8.0, update to version 0.9.0 or later to resolve the issue.
For Eclipse Dataspace Components version 0.9.0, no action is required as the vulnerable code has been removed.
As a temporary workaround, consider disabling the
ConsumerPullTransferTokenValidationApiController function until a patch is available.
Restrict access to the transfer-data-plane module to minimize the risk of exploitation.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Dataspace Components