CVE-2020-27219
14.01.2021, 23:15
In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.
Vendor | Product | Version |
---|---|---|
eclipse | hawkbit | 𝑥 ≤ 0.2.5 |
eclipse | hawkbit | 0.3.0:m1 |
eclipse | hawkbit | 0.3.0:m2 |
eclipse | hawkbit | 0.3.0:m3 |
eclipse | hawkbit | 0.3.0:m4 |
eclipse | hawkbit | 0.3.0:m5 |
eclipse | hawkbit | 0.3.0:m6 |
𝑥
= Vulnerable software versions