Kura
Eclipse · 6 CVEs
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source…
Jul 14, 2026
In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet…
Apr 9, 2024
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and…
Apr 9, 2019
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be use…
Apr 9, 2019
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially…
Apr 9, 2019
The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow…
Sep 11, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-9561 | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log en… | HIGH | 0.28% | Jul 14, 2026 |
| CVE-2024-3046 | In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to re… | HIGH | 0.58% | Apr 9, 2024 |
| CVE-2019-10244 | In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part… | HIGH | 1.82% | Apr 9, 2019 |
| CVE-2019-10243 | In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifical… | MEDIUM | 1.34% | Apr 9, 2019 |
| CVE-2019-10242 | In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests… | MEDIUM | 1.96% | Apr 9, 2019 |
| CVE-2017-7649 | The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be configured. S… | CRITICAL | 1.65% | Sep 11, 2017 |
Showing 1 to 6 of 6 CVEs