6.1

CVE-2020-27219

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eclipse ≫ Hawkbit Version <= 0.2.5
Eclipse ≫ Hawkbit Version 0.3.0 Update m1
Eclipse ≫ Hawkbit Version 0.3.0 Update m2
Eclipse ≫ Hawkbit Version 0.3.0 Update m3
Eclipse ≫ Hawkbit Version 0.3.0 Update m4
Eclipse ≫ Hawkbit Version 0.3.0 Update m5
Eclipse ≫ Hawkbit Version 0.3.0 Update m6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.527
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://bugs.eclipse.org/bugs/show_bug.cgi?id=570289
Vendor Advisory
https://github.com/eclipse/hawkbit/issues/1067
Third Party Advisory