← Back

CVE-2020-27219

nvd nist
Published: Jan 14, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.

Affected (7)

Products: Eclipse: Hawkbit
1 product
Hawkbit
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
Up to 0.2.5
Version 0.3.0 m1
Version 0.3.0 m2
Version 0.3.0 m3
Version 0.3.0 m4
Version 0.3.0 m5
Version 0.3.0 m6

References (4)

Source: emo@eclipse.org
Vendor Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.