ZeroHour

CVE-2019-10242

CVSS 3.0
5.3 medium
EPSS
2%p79
Published
()
Modified
Description

In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.

Vendors
eclipse
Products
kura
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.