Description
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
Remediation
References
http://www.securityfocus.com/bid/107844
https://bugs.eclipse.org/bugs/show_bug.cgi?id=545835
Related Vulnerabilities
CVE-2020-1953 Vulnerability in maven package org.apache.commons:commons-configuration2
CVE-2016-6497 Vulnerability in maven package org.xbib.groovy:groovy-ldap
CVE-2020-2253 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2023-24807 Vulnerability in maven package org.webjars.npm:undici
CVE-2021-41251 Vulnerability in npm package @sap-cloud-sdk/core