6.1

CVE-2020-27219

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EclipseHawkbit Version <= 0.2.5
EclipseHawkbit Version0.3.0 Updatem1
EclipseHawkbit Version0.3.0 Updatem2
EclipseHawkbit Version0.3.0 Updatem3
EclipseHawkbit Version0.3.0 Updatem4
EclipseHawkbit Version0.3.0 Updatem5
EclipseHawkbit Version0.3.0 Updatem6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.516
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.