Medium severity6.1NVD Advisory· Published Jan 14, 2021· Updated Jun 17, 2026
CVE-2020-27219
CVE-2020-27219
Description
In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.eclipse.hawkbit:hawkbit-parentMaven | < 0.3.0M7 | 0.3.0M7 |
Affected products
9cpe:2.3:a:eclipse:hawkbit:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:eclipse:hawkbit:*:*:*:*:*:*:*:*range: <=0.2.5
- cpe:2.3:a:eclipse:hawkbit:0.3.0:m1:*:*:*:*:*:*
- cpe:2.3:a:eclipse:hawkbit:0.3.0:m2:*:*:*:*:*:*
- cpe:2.3:a:eclipse:hawkbit:0.3.0:m3:*:*:*:*:*:*
- cpe:2.3:a:eclipse:hawkbit:0.3.0:m4:*:*:*:*:*:*
- cpe:2.3:a:eclipse:hawkbit:0.3.0:m5:*:*:*:*:*:*
- cpe:2.3:a:eclipse:hawkbit:0.3.0:m6:*:*:*:*:*:*
- The Eclipse Foundation/Eclipse Hawkbitv5Range: All versions prior 0.3.0M7
Patches
Vulnerability mechanics
References
5- bugs.eclipse.org/bugs/show_bug.cginvdVendor AdvisoryWEB
- github.com/advisories/GHSA-rcvx-rmvf-mxchghsaADVISORY
- github.com/eclipse/hawkbit/issues/1067nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-27219ghsaADVISORY
- github.com/eclipse/hawkbit/commit/94b7c12cde1b38eda5414bd88d6d068008cfb9f9ghsaWEB
News mentions
0No linked articles in our index yet.