// For flags

CVE-2024-8642

Eclipse EDC: Consumer pull transfer token validation checks not applied

Severity Score

5.0
*CVSS v4

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module "transfer-data-plane". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
High
User Interaction
None
System
Vulnerable | Subsequent
Confidentiality
None
High
Integrity
None
High
Availability
None
None
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
High
User Interaction
None
System
Vulnerable | Subsequent
Confidentiality
None
High
Integrity
None
High
Availability
None
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
Poc
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-09-10 CVE Reserved
  • 2024-09-11 CVE Published
  • 2024-09-11 CVE Updated
  • 2024-09-12 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-303: Incorrect Implementation of Authentication Algorithm
  • CWE-305: Authentication Bypass by Primary Weakness
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eclipse Foundation
Search vendor "Eclipse Foundation"
Eclipse EDC Connector
Search vendor "Eclipse Foundation" for product "Eclipse EDC Connector"
>= 0.5.0 < 0.9.0
Search vendor "Eclipse Foundation" for product "Eclipse EDC Connector" and version " >= 0.5.0 < 0.9.0"
en
Affected