Description
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module "transfer-data-plane". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed.
Scores
CVSS v3
8.1
EPSS
0.0011
EPSS Percentile
29.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-287
CWE-303
CWE-305
Status
published
Products (2)
eclipse/eclipse_dataspace_components
0.5.0 - 0.9.0
org.eclipse.edc/transfer-data-plane
0.5.0 - 0.9.0Maven
Published
Sep 11, 2024
Tracked Since
Feb 18, 2026