Impact
A flaw in Eclipse Lyo permits an attacker to register a provisional OAuth client and immediately elevate it to a trusted client without the required administrative approval. This bypasses the intended authorization logic that protects resources via Lyo’s `AbstractAdapterCredentialsFilter`. The resulting capability lets an unauthenticated attacker access protected APIs and data that should be guarded by full OAuth client validation.
Affected Systems
Vulnerable Eclipse Lyo releases span from 2.0.0 up through 7.0.0. The publicly released v6.0.1.Final contains the vendor‑supplied fix, and the subsequent v7.0.0.Beta3 release also resolves the issue. Any installation of Lyo older than 6.0.1.Final or without this update is at risk.
Risk and Exploitability
With a CVSS score of 9.1 the flaw is considered critical. Although the EPSS score is not available, the high severity and the direct bypass of administrative approval suggest a considerable likelihood of exploitation, especially if the provisional client registration endpoint is reachable. The 3‑legged OAuth flow remains unaffected and rejects provisional clients, but the 2‑legged flow provides a clear attack vector.
OpenCVE Enrichment