XXE Vulnerability in Eclipse Kura Affects Web UI and Component Services
CVE-2019-10244
7.5HIGH
What is CVE-2019-10244?
In versions of Eclipse Kura up to 4.0.0, multiple components such as the Web UI package, Artemis simple Mqtt component, and emulator position service are susceptible to XML External Entity (XXE) attacks. This vulnerability arises from improper initialization of the factory and parser, potentially allowing attackers to exploit these components. Ensuring proper configuration and updating to secure versions is essential to mitigate these risks.
Affected Version(s)
Eclipse Kura <= 4.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved