EDC DataSetResolver 策略过滤缺失(CVE-2024-9202)

admin 2024-09-29 01:12:10 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
EDC DataSetResolver 策略过滤缺失(CVE-2024-9202)

CVE编号

CVE-2024-9202

利用情况

暂无

补丁情况

N/A

披露时间

2024-09-27
漏洞描述
In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to request a single dataset, which should be subject to the same filtering process, but currently is missing the correct filtering. This enables parties to potentially see datasets they should not have access to, thereby exposing sensitive information. Exploiting this vulnerability requires knowing the ID of a restricted dataset, but some IDs may be guessed by trying out many IDs in an automated way. Affected code: DatasetResolverImpl, L76-79 https://github.com/eclipse-edc/Connector/blob/v0.9.0/core/control-plane/control-plane-catalog/src/main/java/org/eclipse/edc/connector/controlplane/catalog/DatasetResolverImpl.java
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/eclipse-edc/Connector/pull/4490
https://github.com/eclipse-edc/Connector/pull/4491
https://gitlab.eclipse.org/security/cve-assignement/-/issues/35
CVSS3评分 N/A
  • 攻击路径 N/A
  • 攻击复杂度 N/A
  • 权限要求 N/A
  • 影响范围 N/A
  • 用户交互 N/A
  • 可用性 N/A
  • 保密性 N/A
  • 完整性 N/A
N/A
CWE-ID 漏洞类型
- avd.aliyun.com
评论:0   参与:  44