First published: Tue Apr 09 2019(Updated: )
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Kura | <=4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10243 has a moderate severity, as it exposes the underlying web server version which can be exploited.
To fix CVE-2019-10243, upgrade to a version of Eclipse Kura that is newer than 4.0.0, where this vulnerability is resolved.
CVE-2019-10243 could allow an attacker to specifically target the web server with tailored attacks due to version exposure.
If you are using Eclipse Kura versions up to 4.0.0, then your version is affected by CVE-2019-10243.
You can verify CVE-2019-10243 by checking the responses from your Kura deployment for the exposed web server version.