Impact
The Eclipse BaSyx AAS Web UI at versions v2‑241220 through just before v2‑260924 contains a request handler that indiscriminately forwards the selected infrastructure's Authorization header to any destination accessed via the "aas" or "path" query parameters. This behavior constitutes a CWE‑201 weakness: unauthorized disclosure of credentials over an insecure channel. An attacker can construct a fabricated Web UI link that points to an external, attacker‑controlled endpoint; when the victim's browser follows the link the Basic Authentication, Bearer token, or OAuth2 access token is sent unfiltered. The attacker obtains these credentials and can subsequently access protected Asset Administration Shell services with the victim’s privileges, leading to credential leakage and unauthorized access.
Affected Systems
The affected product is the Eclipse Foundation’s BaSyx AAS Web UI. Vulnerable releases span from v2‑241220 up to, but not including, v2‑260924. The bug was addressed in the v2‑260924 release. The issue applies only to deployments that enable authentication, as the forwarded header contains user credentials.
Risk and Exploitability
The CVSS score of 8.3 classifies this as high severity. No EPSS score has been published, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires minimal effort—an attacker must convince a user to click a malicious link, a low‑barrier social‑engineering technique. Once the request includes the victim’s Authorization header, the attacker immediately receives the token or credentials and can access any AAS resources the user is authorized for. The likelihood of exploitation is therefore significant, especially in environments with wide user bases and no additional monitoring of outgoing requests.
OpenCVE Enrichment