SCA: security update for org.eclipse.edc:connector-core (GHSA-2x52-8f29-7cjr)

medium Tenable Self-Hosted Container Security Plugin ID 409154

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component (
https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from the vault.
In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have identified a security vulnerability
in the EDC Connector component ( https://github.com/eclipse-edc/Connector ) regarding the OAuth2-protected
data sink feature. When using a custom, OAuth2-protected data sink, the OAuth2-specific data address
properties are resolved by the provider data plane. Problematically, the consumer-provided
clientSecretKey, which indicates the OAuth2 client secret to retrieve from a secrets vault, is resolved in
the context of the provider's vault, not the consumer. This secret's value is then sent to the tokenUrl,
also consumer-controlled, as part of an OAuth2 client credentials grant. The returned access token is then
sent as a bearer token to the data sink URL. This feature is now disabled entirely, because not all code
paths necessary for a successful realization were fully implemented. (CVE-2024-4536)

See Also

https://github.com/advisories/GHSA-2x52-8f29-7cjr

Plugin Details

Severity: Medium

ID: 409154

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.71

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 3.8

Vector: CVSS2#AV:A/AC:H/Au:M/C:C/I:P/A:P

CVSS Score Source: CVE-2024-4536

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/7/2024

Vulnerability Publication Date: 5/7/2024

Reference Information

CVE: CVE-2024-4536