Lucene search

K
githubGitHub Advisory DatabaseGHSA-RCVX-RMVF-MXCH
HistoryFeb 09, 2022 - 10:19 p.m.

Cross-site Scripting in Eclipse Hawkbit

2022-02-0922:19:44
CWE-79
GitHub Advisory Database
github.com
19
cross-site scripting
eclipse hawkbit
http 404
rest api
json response
unsafe characters
path attribute
post request
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

32.2%

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.

Affected configurations

Vulners
Node
org.eclipse.hawkbithawkbit-parentRange0.3.0M6
VendorProductVersionCPE
org.eclipse.hawkbithawkbit-parent*cpe:2.3:a:org.eclipse.hawkbit:hawkbit-parent:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

32.2%

Related for GHSA-RCVX-RMVF-MXCH