PT-2024-7968 · Eclipse · Eclipse Dataspace Components

Marta Rybczynska

·

Published

2024-09-11

·

Updated

2024-09-19

·

CVE-2024-8642

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Dataspace Components versions 0.5.0 through 0.9.0
Description The issue is related to the ConsumerPullTransferTokenValidationApiController component, which has inadequate authentication procedures. This allows a remote attacker to bypass the token expiration check. The vulnerability requires a dataplane configured to support http proxy consumer pull and includes the module "transfer-data-plane". The affected code was marked deprecated from version 0.6.0 in favor of Dataplane Signaling and was removed in version 0.9.0.
Recommendations For Eclipse Dataspace Components versions 0.5.0 through 0.8.0, update to version 0.9.0 or later to resolve the issue. For Eclipse Dataspace Components version 0.9.0, no action is required as the vulnerable code has been removed. As a temporary workaround, consider disabling the ConsumerPullTransferTokenValidationApiController function until a patch is available. Restrict access to the transfer-data-plane module to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-09481
CVE-2024-8642
GHSA-8259-2X72-2GVC

Affected Products

Eclipse Dataspace Components