CVE-2020-27219

I

n all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eclipse:hawkbit:*:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:hawkbit:0.3.0:m1:*:*:*:*:*:*
cpe:2.3:a:eclipse:hawkbit:0.3.0:m2:*:*:*:*:*:*
cpe:2.3:a:eclipse:hawkbit:0.3.0:m3:*:*:*:*:*:*
cpe:2.3:a:eclipse:hawkbit:0.3.0:m4:*:*:*:*:*:*
cpe:2.3:a:eclipse:hawkbit:0.3.0:m5:*:*:*:*:*:*
cpe:2.3:a:eclipse:hawkbit:0.3.0:m6:*:*:*:*:*:*

History

21 Nov 2024, 05:20

Type Values Removed Values Added
References () https://bugs.eclipse.org/bugs/show_bug.cgi?id=570289 - Vendor Advisory () https://bugs.eclipse.org/bugs/show_bug.cgi?id=570289 - Vendor Advisory
References () https://github.com/eclipse/hawkbit/issues/1067 - Third Party Advisory () https://github.com/eclipse/hawkbit/issues/1067 - Third Party Advisory

Information

Published : 2021-01-14 23:15

Updated : 2024-11-21 05:20


NVD link : CVE-2020-27219

Mitre link : CVE-2020-27219

CVE.ORG link : CVE-2020-27219


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')