

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.

Source: CVE-2019-10244

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다