CVE-2019-10244: XEE
Published Apr 9, 2019
·Updated
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.
Affected Software
1 affected component
Eclipse Kura<=4.0.0
Event History
Apr 9, 2019
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-10244?
CVE-2019-10244 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-10244?
To fix CVE-2019-10244, upgrade Eclipse Kura to version 4.0.1 or later.
3
What components are affected by CVE-2019-10244?
CVE-2019-10244 affects the Web UI package, Artemis simple Mqtt component, and emulator position service in Eclipse Kura.
4
What type of vulnerability is CVE-2019-10244?
CVE-2019-10244 is an XML External Entity (XXE) vulnerability due to improper factory and parser initialization.
5
Which versions of Eclipse Kura are vulnerable to CVE-2019-10244?
Eclipse Kura versions up to and including 4.0.0 are vulnerable to CVE-2019-10244.