Impact
A flaw in the QueuePushReqStreamObserver.initEggroll routine of the OSX Broker component in FederatedAI FATE allows an attacker to manipulate the dstRole and dstPartyId parameters, causing data elements to be exposed to unintended sessions. This session-handling weakness (CWE-488) can lead to confidential data leaking between parties that should not share that data.
Affected Systems
The vulnerability affects deployments of FederatedAI FATE up to and including version 2.2.0. If the OSX Broker component is used in a production environment, administrators should verify that no vulnerable session handling code is active.
Risk and Exploitability
The CVSS score of 2.3 places this flaw in the low severity range, and the EPSS score is less than 1%, indicating that the likelihood of widespread exploitation is currently low. The flaw is not listed in any current KEV catalog. The attack can be and the exploitation conditions are considered difficult; however, that now if the conditions are met.
OpenCVE Enrichment