Impact
The Eclipse Ditto Node.js JavaScript client hard‑codes the WebSocket option rejectUnauthorized to false, disabling certificate and hostname verification for all wss:// connections. This flaw permits an attacker who can intercept the traffic to perform a man‑in‑the‑middle attack, complete the TLS handshake with any certificate, and then read or inject Authorization headers and Ditto Protocol messages. The weakness is a combination of insecure default configuration (CWE‑295), lack of proper authentication (CWE‑297) and weak certificate handling (CWE‑300). The result can be full disclosure of credentials, tampering with device data, and arbitrary command injection into the Ditto protocol.
Affected Systems
Eclipse Foundation’s Eclipse Ditto product, specifically the Node.js JavaScript client packages @eclipse-ditto/ditto-javascript-client-node versions 2.0.0 through 3.9.0 and the predecessor @eclipse-ditto/ditto-javascript-client-node_1.0 versions 1.0.0 through 2.1.0. The Java client, browser/DOM JavaScript client, and HTTP transport of the Node.js client are not affected.
Risk and Exploitability
With a CVSS score of 9.2 the vulnerability is considered critical. Although EPSS data is not available, the absence of KEV listing does not reduce the risk: the flaw can be exploited remotely by any entity able to observe or intercept the WebSocket traffic, enabling full read/write access to the connection. Attackers could therefore exfiltrate credentials or manipulate device state without detection if TLS validation remains disabled.
OpenCVE Enrichment