Impact
A2aJava’s AuthorizationRequestHandlerDecorator.onListTasks method omits a proper authorization check, allowing a remote attacker to call the task‑listing endpoint without credentials. The missing control lets an adversary enumerate internal tasks, potentially exposing sensitive operational data and providing a foothold for further attacks. The weakness corresponds to the conditions restrictions and missing authorization weaknesses identified as CWE‑862 and CWE‑863.
Affected Systems
The vulnerable component is a2a-java version 1.2.0. Upgrading to release 1.3.0.Final applies the patch commit e9a1abf9c90c02b16d17293afdc3cc2f555d63a6, restoring proper authorization and eliminating the flaw. No other vendor or product versions are documented as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, and the missing authorization can be exploited to retrieve task information without authentication. Because the impact is limited to task enumeration rather than full system compromise, the overall risk is moderate but still requires timely patching.
OpenCVE Enrichment