Lucene search

K
cveEclipseCVE-2020-27219
HistoryJan 14, 2021 - 11:15 p.m.

CVE-2020-27219

2021-01-1423:15:12
CWE-79
eclipse
web.nvd.nist.gov
68
4
cve-2020-27219
eclipse hawkbit
http 404
json response
vulnerability
rest api
unsafe characters
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

32.2%

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.

Affected configurations

Nvd
Node
eclipsehawkbitRange0.2.5
OR
eclipsehawkbitMatch0.3.0m1
OR
eclipsehawkbitMatch0.3.0m2
OR
eclipsehawkbitMatch0.3.0m3
OR
eclipsehawkbitMatch0.3.0m4
OR
eclipsehawkbitMatch0.3.0m5
OR
eclipsehawkbitMatch0.3.0m6
VendorProductVersionCPE
eclipsehawkbit*cpe:2.3:a:eclipse:hawkbit:*:*:*:*:*:*:*:*
eclipsehawkbit0.3.0cpe:2.3:a:eclipse:hawkbit:0.3.0:m1:*:*:*:*:*:*
eclipsehawkbit0.3.0cpe:2.3:a:eclipse:hawkbit:0.3.0:m2:*:*:*:*:*:*
eclipsehawkbit0.3.0cpe:2.3:a:eclipse:hawkbit:0.3.0:m3:*:*:*:*:*:*
eclipsehawkbit0.3.0cpe:2.3:a:eclipse:hawkbit:0.3.0:m4:*:*:*:*:*:*
eclipsehawkbit0.3.0cpe:2.3:a:eclipse:hawkbit:0.3.0:m5:*:*:*:*:*:*
eclipsehawkbit0.3.0cpe:2.3:a:eclipse:hawkbit:0.3.0:m6:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Eclipse Hawkbit",
    "vendor": "The Eclipse Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior 0.3.0M7"
      }
    ]
  }
]

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

32.2%

Related for CVE-2020-27219