PT-2024-23389 · Eclipse · Eclipse Kura+1

Davide Virruso

·

Published

2024-04-09

·

Updated

2025-02-06

·

CVE-2024-3046

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Kura versions 5.0.0 through 5.4.1 org.eclipse.kura:org.eclipse.kura.web2 versions 2.0.600 through 2.4.0
Description A specifically crafted request to the LogServlet component can allow an unauthenticated user to retrieve the device logs. The downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user reported in logs.
Recommendations For Eclipse Kura versions 5.0.0 through 5.4.1, update to version 5.4.2 to resolve the issue. For org.eclipse.kura:org.eclipse.kura.web2 versions 2.0.600 through 2.4.0, update to a version that is not included in the affected range, as the specific fixed version for this component is not provided. As a temporary workaround, consider restricting access to the LogServlet component until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-3046
GHSA-FRC2-W2CC-X794

Affected Products

Eclipse Kura
Org.Eclipse.Kura.Web2