org.eclipse.edc:data-plane-http-oauth2-core@0.6.2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.eclipse.edc:data-plane-http-oauth2-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure Through Sent Data

Affected versions of this package are vulnerable to Information Exposure Through Sent Data by resolving the clientSecretKey in the context of a provider's vault when it should be resolved in the consumer's. A user in the same dataspace can expose OAuth2-protected client data, which is sent to a consumer-controlled tokenUrl as part of an OAuth2 client credentials grant, and subsequently used as a bearer token.

How to fix Information Exposure Through Sent Data?

Upgrade org.eclipse.edc:data-plane-http-oauth2-core to version 0.6.3 or higher.

[0.2.1,0.6.3)