Improper Input Validation in Eclipse Hawkbit REST API
CVE-2020-27219

6.1MEDIUM

Key Information:

Vendor
CVE Published:
14 January 2021

What is CVE-2020-27219?

In all versions of Eclipse Hawkbit prior to 0.3.0M7, a flaw exists in the handling of HTTP 404 (Not Found) responses generated by its REST API. When a POST request is made to a non-existing resource, the response may unintentionally reveal the full URL path as an unescaped string. This leak of unsafe characters poses a risk that could be exploited by malicious actors to potentially inject harmful payloads or to conduct further targeted attacks.

Affected Version(s)

Eclipse Hawkbit All versions prior 0.3.0M7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.