In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.
References
Link Resource
http://www.securityfocus.com/bid/107844 Third Party Advisory VDB Entry
https://bugs.eclipse.org/bugs/show_bug.cgi?id=545835 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: eclipse

Published: 2019-04-09T15:42:42

Updated: 2019-04-10T15:06:15

Reserved: 2019-03-27T00:00:00


Link: CVE-2019-10244

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-04-09T16:29:01.587

Modified: 2019-10-09T23:44:33.617


Link: CVE-2019-10244

JSON object: View

cve-icon Redhat Information

No data.

CWE