diff --git a/advisories/github-reviewed/2024/05/GHSA-2x52-8f29-7cjr/GHSA-2x52-8f29-7cjr.json b/advisories/github-reviewed/2024/05/GHSA-2x52-8f29-7cjr/GHSA-2x52-8f29-7cjr.json index e8ecd417422..03aca4c1d95 100644 --- a/advisories/github-reviewed/2024/05/GHSA-2x52-8f29-7cjr/GHSA-2x52-8f29-7cjr.json +++ b/advisories/github-reviewed/2024/05/GHSA-2x52-8f29-7cjr/GHSA-2x52-8f29-7cjr.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-2x52-8f29-7cjr", - "modified": "2024-05-07T16:51:10Z", + "modified": "2025-02-06T19:33:44Z", "published": "2024-05-07T15:30:36Z", "aliases": [ "CVE-2024-4536" ], "summary": "Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosure", - "details": "In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the [EDC Connector component](https://github.com/eclipse-edc/Connector), an attacker might obtain OAuth2 client secrets from the vault.\n\nIn Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have identified a security vulnerability in the EDC Connector component ( https://github.com/eclipse-edc/Connector ) regarding the OAuth2-protected data sink feature. When using a custom, OAuth2-protected data sink, the OAuth2-specific data address properties are resolved by the provider data plane. Problematically, the consumer-provided clientSecretKey, which indicates the OAuth2 client secret to retrieve from a secrets vault, is resolved in the context of the provider's vault, not the consumer. This secret's value is then sent to the tokenUrl, also consumer-controlled, as part of an OAuth2 client credentials grant. The returned access token is then sent as a bearer token to the data sink URL.\n\nThis feature is now disabled entirely, because not all code paths necessary for a successful realization were fully implemented.\n\n", + "details": "In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the [EDC Connector component](https://github.com/eclipse-edc/Connector), an attacker might obtain OAuth2 client secrets from the vault.\n\nIn Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have identified a security vulnerability in the EDC Connector component ( https://github.com/eclipse-edc/Connector ) regarding the OAuth2-protected data sink feature. When using a custom, OAuth2-protected data sink, the OAuth2-specific data address properties are resolved by the provider data plane. Problematically, the consumer-provided clientSecretKey, which indicates the OAuth2 client secret to retrieve from a secrets vault, is resolved in the context of the provider's vault, not the consumer. This secret's value is then sent to the tokenUrl, also consumer-controlled, as part of an OAuth2 client credentials grant. The returned access token is then sent as a bearer token to the data sink URL.\n\nThis feature is now disabled entirely, because not all code paths necessary for a successful realization were fully implemented.", "severity": [ { "type": "CVSS_V3", @@ -63,7 +63,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-201" + "CWE-201", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": true,