org.eclipse.edc:data-plane-http-oauth2-core@0.6.1 vulnerabilities

  • latest version

    0.13.0

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.eclipse.edc:data-plane-http-oauth2-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Information Exposure Through Sent Data

    Affected versions of this package are vulnerable to Information Exposure Through Sent Data by resolving the clientSecretKey in the context of a provider's vault when it should be resolved in the consumer's. A user in the same dataspace can expose OAuth2-protected client data, which is sent to a consumer-controlled tokenUrl as part of an OAuth2 client credentials grant, and subsequently used as a bearer token.

    How to fix Information Exposure Through Sent Data?

    Upgrade org.eclipse.edc:data-plane-http-oauth2-core to version 0.6.3 or higher.

    [0.2.1,0.6.3)