Intel

AIKIDO-2025-10466

OfX is vulnerable to Missing Encryption of Sensitive Data

Missing Encryption of Sensitive Data Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 16, 2025

87

High Risk

This Affects:

DOTNETOfX
3.1.8 - 7.0.2
Fixed in 7.0.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package do not encrypt sensitive data transmitted via the Messaging modules (NATS, RabbitMQ, Kafka), potentially exposing confidential information in transit. Without proper encryption, attackers may intercept or tamper with signed requests, leading to data leaks or unauthorized actions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

OfX is vulnerable to Missing Encryption of Sensitive Data in versions 3.1.8 - 7.0.2.

How to fix this

Upgrade the OfX library to the patch version.