VulnerabilityModified
CVE-2020-27219
In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute.
MEDIUM 6.1EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- eclipse/hawkbit
- Source
- emo@eclipse.org
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=570289Vendor Advisory
- https://github.com/eclipse/hawkbit/issues/1067Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=570289Vendor Advisory
- https://github.com/eclipse/hawkbit/issues/1067Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.