Impact
A flaw in the QueuePushReqStreamObserver.initEggroll routine of the OSX Broker component in FederatedAI FATE allows an attacker to manipulate the dstRole and dstPartyId parameters, causing data elements to be exposed to unintended sessions. This session-handling weakness (CWE-488) can lead to confidential data leaking between parties that should not share that data.
Affected Systems
The vulnerability affects deployments of FederatedAI FATE up to and including version 2.2.0 where the OSX Broker component is in use. The affected component is the QueuePushReqStreamObserver in the OSX Broker.
Risk and Exploitability
The CVSS score of 2.3 places this flaw in the low severity range, and the EPSS score is less than 1%, indicating that the likelihood of widespread exploitation is currently low. The flaw is not listed in any current KEV catalog. The exploit is remote, requiring manipulation of the rollSiteSessionId, dstRole, and dstPartyId parameters; while the attack has high complexity and is considered difficult, a remote attacker who can reach the OSX Broker endpoint could potentially manipulate session identifiers and expose data elements to an unintended session.
OpenCVE Enrichment