Impact
The Siglet component in Eclipse Data Plane Core lacks enforcement of proof of possession for the issuer DID when handling refresh tokens. This flaw means an attacker who has obtained a valid refresh token can use it without proving control over the issuer’s DID, effectively bypassing intended authentication checks. The impact is the potential for unauthorized access or privilege escalation within systems that rely on these refresh tokens for session continuity, compromising confidentiality and integrity of protected resources.
Affected Systems
Vendors impacted include Eclipse Foundation’s Eclipse Data Plane Core product line, specifically the Siglet module. Affected versions span current and past releases; the precise version range is not enumerated in the advisories.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an adversary can exploit a compromised refresh token over a network. Exploitation requires possession of a refresh token and does not rely on further system access, making the risk of compromise significant for deployments that do not enforce DID proof.
OpenCVE Enrichment