In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user reported in logs.
This issue affects org.eclipse.kura:org.eclipse.kura.web2 version range [2.0.600, 2.4.0], which is included in Eclipse Kura version range [5.0.0, 5.4.1]
References
Link | Resource |
---|---|
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188 | Issue Tracking Vendor Advisory |
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188 | Issue Tracking Vendor Advisory |
Configurations
History
06 Feb 2025, 18:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188 - Issue Tracking, Vendor Advisory | |
First Time |
Eclipse kura
Eclipse |
|
CPE | cpe:2.3:a:eclipse:kura:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo |
Information
Published : 2024-04-09 10:15
Updated : 2025-02-06 18:07
NVD link : CVE-2024-3046
Mitre link : CVE-2024-3046
CVE.ORG link : CVE-2024-3046
JSON object : View
Products Affected
eclipse
- kura
CWE