CVE-2024-4536 is a medium-severity vulnerability affecting Eclipse Dataspace Components EDC Connector versions 0.2.1 to 0.6.2. An attacker with high privileges and network access can exploit a flaw in the OAuth2-protected data sink feature to potentially obtain OAuth2 client secrets from the provider's vault. This could lead to high confidentiality impact and low integrity/availability impacts, as the consumer-controlled tokenUrl receives the secret. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.2.1, < 0.6.3CPE matchmatch criteria | cpe:2.3:a:eclipse:edc_connector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.