Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-8642
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Eclipse EDC: Consumer pull transfer token validation checks not applied
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane configured to support http proxy consumer pull AND include the module "transfer-data-plane". The affected code was marked deprecated from the version 0.6.0 in favour of Dataplane Signaling. In 0.9.0 the vulnerable code has been removed.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
认证算法的不正确实现
Source: NVD (National Vulnerability Database)
Vulnerability Title
Eclipse Dataspace Components 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Eclipse Dataspace Components是Eclipse Dataspace Components开源的一个开发连接器。 Eclipse Dataspace Components 0.5.0版本至0.9.0之前版本存在安全漏洞,该漏洞源于不检查令牌有效性,这可以让攻击者绕过对令牌到期的检查。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Eclipse FoundationEclipse EDC Connector 0.5.0 ~ 0.9.0 -
II. Public POCs for CVE-2024-8642
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-8642
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-8642

No comments yet


Leave a comment