VulnerabilityModified
CVE-2019-10243
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies.
MEDIUM 5.3EPSS 1.34%
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-497, CWE-200
- Affected
- eclipse/kura
- Source
- emo@eclipse.org
References
- http://www.securityfocus.com/bid/107844Third Party Advisory, VDB Entry
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=545834Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/107844Third Party Advisory, VDB Entry
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=545834Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.