CVE-2026-82958
- EPSS 0.24%
- Veröffentlicht 02.09.2026 10:12:49
- Zuletzt bearbeitet 03.09.2026 16:41:09
In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pr...
CVE-2026-84175
- EPSS 0.29%
- Veröffentlicht 02.09.2026 09:45:58
- Zuletzt bearbeitet 03.09.2026 16:41:09
In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirec...
CVE-2024-5165
- EPSS 0.5%
- Veröffentlicht 23.05.2024 10:15:10
- Zuletzt bearbeitet 31.01.2025 14:46:11
In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Interface https://eclipse.dev/ditto/user-interface.html was not properly neutralized and thus vulnerable to both Reflected and Store...