-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.eclipse.edc:transfer-data-plane | maven | >= 0.5.0, < 0.9.0 | 0.9.0 |
The vulnerability stems from ConsumerPullTransferTokenValidationApiController's token validation implementation. The controller calls TokenValidationService.validate(token, publicKeyResolver) without providing validation rules (third parameter), despite rules being registered for the 'dataplane-transfer' context. This omission prevents critical checks like token expiration from being executed. The removed code in commit 04899e9 confirms this was the vulnerable component, and the CVE description explicitly references this controller as the flawed implementation.
Ongoing coverage of React2Shell