CVE-2019-10243: Infoleak
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10243?
CVE-2019-10243 has a moderate severity, as it exposes the underlying web server version which can be exploited.
How do I fix CVE-2019-10243?
To fix CVE-2019-10243, upgrade to a version of Eclipse Kura that is newer than 4.0.0, where this vulnerability is resolved.
What potential impact does CVE-2019-10243 have on my system?
CVE-2019-10243 could allow an attacker to specifically target the web server with tailored attacks due to version exposure.
Is my version of Eclipse Kura affected by CVE-2019-10243?
If you are using Eclipse Kura versions up to 4.0.0, then your version is affected by CVE-2019-10243.
How can I verify if my deployment is vulnerable to CVE-2019-10243?
You can verify CVE-2019-10243 by checking the responses from your Kura deployment for the exposed web server version.