Description
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
Remediation
References
http://www.securityfocus.com/bid/107844
https://bugs.eclipse.org/bugs/show_bug.cgi?id=545835
Related Vulnerabilities
CVE-2020-2193 Vulnerability in maven package io.jenkins.plugins:echarts-api
CVE-2022-29161 Vulnerability in maven package org.xwiki.platform:xwiki-platform-crypto
CVE-2015-8858 Vulnerability in maven package org.webjars.npm:uglify-js
CVE-2019-10431 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2015-2080 Vulnerability in maven package org.eclipse.jetty.aggregate:jetty-all