Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2751 | In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module "transfer-data-plane". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed. |
Github GHSA |
GHSA-8259-2x72-2gvc | Eclipse Dataspace Components's ConsumerPullTransferTokenValidationApiController doesn't check for token validit |
Thu, 19 Sep 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse eclipse Dataspace Components |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:eclipse:eclipse_dataspace_components:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eclipse
Eclipse eclipse Dataspace Components |
|
| Metrics |
cvssV3_1
|
Thu, 12 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse Foundation
Eclipse Foundation edc |
|
| CPEs | cpe:2.3:a:eclipse_foundation:edc:0.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Eclipse Foundation
Eclipse Foundation edc |
|
| Metrics |
ssvc
|
Wed, 11 Sep 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module "transfer-data-plane". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed. | |
| Title | Eclipse EDC: Consumer pull transfer token validation checks not applied | |
| Weaknesses | CWE-303 CWE-305 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-09-11T14:06:55.373Z
Reserved: 2024-09-10T06:20:33.205Z
Link: CVE-2024-8642
Updated: 2024-09-11T14:06:44.769Z
Status : Analyzed
Published: 2024-09-11T14:15:14.177
Modified: 2026-04-29T01:00:01.613
Link: CVE-2024-8642
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA