In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user reported in logs.
This issue affects org.eclipse.kura:org.eclipse.kura.web2 version range [2.0.600, 2.4.0], which is included in Eclipse Kura version range [5.0.0, 5.4.1]
References
Link | Resource |
---|---|
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188 | Issue Tracking Vendor Advisory |
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188 | Issue Tracking Vendor Advisory |
Configurations
History
06 Feb 2025, 18:07
Type | Values Removed | Values Added |
---|---|---|
First Time |
Eclipse
Eclipse kura |
|
CWE | NVD-CWE-noinfo | |
References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188 - Issue Tracking, Vendor Advisory | |
CPE | cpe:2.3:a:eclipse:kura:*:*:*:*:*:*:*:* |
21 Nov 2024, 09:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188 - | |
Summary |
|
10 Apr 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
Summary | (en) In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user reported in logs. This issue affects org.eclipse.kura:org.eclipse.kura.web2 version range [2.0.600, 2.4.0], which is included in Eclipse Kura version range [5.0.0, 5.4.1] |
09 Apr 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-09 10:15
Updated : 2025-02-06 18:07
NVD link : CVE-2024-3046
Mitre link : CVE-2024-3046
CVE.ORG link : CVE-2024-3046
JSON object : View
Products Affected
eclipse
- kura
CWE