CVE-2020-27219 Information
Jun 07, 2022
cve
Description
In all version of Eclipse Hawkbit prior to 0.3.0M7 the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://bugs.eclipse.org/bugs/show_bug.cgi?id=570289 https://github.com/eclipse/hawkbit/issues/1067
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: