Описание
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.
Ссылки
- Third Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.0 (включая)
cpe:2.3:a:eclipse:kura:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00219
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611
CWE-611
Связанные уязвимости
CVSS3: 7.5
github
около 3 лет назад
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.
EPSS
Процентиль: 45%
0.00219
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611
CWE-611