VYPR
Medium severity6.1NVD Advisory· Published Jan 14, 2021· Updated Jun 17, 2026

CVE-2020-27219

CVE-2020-27219

Description

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.eclipse.hawkbit:hawkbit-parentMaven
< 0.3.0M70.3.0M7

Affected products

9
  • Eclipse/hawkBit7 versions
    cpe:2.3:a:eclipse:hawkbit:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:eclipse:hawkbit:*:*:*:*:*:*:*:*range: <=0.2.5
    • cpe:2.3:a:eclipse:hawkbit:0.3.0:m1:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:hawkbit:0.3.0:m2:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:hawkbit:0.3.0:m3:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:hawkbit:0.3.0:m4:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:hawkbit:0.3.0:m5:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:hawkbit:0.3.0:m6:*:*:*:*:*:*
  • The Eclipse Foundation/Eclipse Hawkbitv5
    Range: All versions prior 0.3.0M7

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.