XXE Vulnerability in Eclipse Kura Affects Web UI and Component Services
CVE-2019-10244
7.5HIGH
What is CVE-2019-10244?
In versions of Eclipse Kura up to 4.0.0, multiple components such as the Web UI package, Artemis simple Mqtt component, and emulator position service are susceptible to XML External Entity (XXE) attacks. This vulnerability arises from improper initialization of the factory and parser, potentially allowing attackers to exploit these components. Ensuring proper configuration and updating to secure versions is essential to mitigate these risks.
Affected Version(s)
Eclipse Kura <= 4.0.0