{"Unauthenticated User Can Retrieve Device Logs","Privilege Escalation via Logs"}
CVE-2024-3046
7.5HIGH
What is CVE-2024-3046?
The Eclipse Kura LogServlet component presents a vulnerability in versions ranging from 5.0.0 to 5.4.1, where an unauthenticated user can craft specific requests to access device logs. This unauthorized access to logs can potentially enable an attacker to escalate privileges by exploiting the session IDs of authenticated users contained within the logs. The affected package, org.eclipse.kura.web2, spans version numbers [2.0.600] to [2.4.0], which further highlights the scope of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kura 5.0.0 <= 5.4.1
