CVE-2019-10242: Path Traversal
Published Apr 9, 2019
·Updated
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
Affected Software
1 affected component
Eclipse Kura<=4.0.0
Event History
Apr 9, 2019
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-10242?
CVE-2019-10242 is considered a medium severity vulnerability.
2
How do I fix CVE-2019-10242?
To fix CVE-2019-10242, upgrade Eclipse Kura to version 4.0.1 or later.
3
What software is affected by CVE-2019-10242?
Eclipse Kura versions up to 4.0.0 are affected by CVE-2019-10242.
4
What type of vulnerability is CVE-2019-10242?
CVE-2019-10242 is a path traversal vulnerability that affects specific file types.
5
What could an attacker achieve with CVE-2019-10242?
An attacker could potentially exploit CVE-2019-10242 to access unauthorized files on the server.