GHSA-4mq9-66fv-8x9q
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.