{"id":"CVE-2020-27219","details":"In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.","aliases":["GHSA-rcvx-rmvf-mxch"],"modified":"2026-08-27T08:40:18.133405Z","published":"2021-01-14T23:15:12.977Z","references":[{"type":"ADVISORY","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=570289"},{"type":"ADVISORY","url":"https://github.com/eclipse/hawkbit/issues/1067"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-hawkbit/hawkbit","events":[{"introduced":"0"},{"last_affected":"347fac7f009e0cefbdf0b238d1b0878b5a176e0f"},{"introduced":"df23c4ef836f25b5630e86614c2a6e1944bfbd62"},{"last_affected":"f3659f01425ad0162f92fa73357f8c507058bcb2"}],"database_specific":{"cpe":["cpe:2.3:a:eclipse:hawkbit:*:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:hawkbit:0.3.0:m1:*:*:*:*:*:*","cpe:2.3:a:eclipse:hawkbit:0.3.0:m2:*:*:*:*:*:*","cpe:2.3:a:eclipse:hawkbit:0.3.0:m3:*:*:*:*:*:*","cpe:2.3:a:eclipse:hawkbit:0.3.0:m4:*:*:*:*:*:*","cpe:2.3:a:eclipse:hawkbit:0.3.0:m5:*:*:*:*:*:*","cpe:2.3:a:eclipse:hawkbit:0.3.0:m6:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"0.2.5"},{"introduced":"0.3.0-m1"},{"last_affected":"0.3.0-m1"},{"introduced":"0.3.0-m2"},{"last_affected":"0.3.0-m2"},{"introduced":"0.3.0-m3"},{"last_affected":"0.3.0-m3"},{"introduced":"0.3.0-m4"},{"last_affected":"0.3.0-m4"},{"introduced":"0.3.0-m5"},{"last_affected":"0.3.0-m5"},{"introduced":"0.3.0-m6"},{"last_affected":"0.3.0-m6"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["0.3.0-m1","0.3.0-m2","0.3.0-m3","0.3.0-m4","0.3.0-m5","0.3.0-m6","0.3.0M6","0.3.0M5","0.3.0M4","0.3.0M3","0.3.0M2","0.3.0M1","0.2.5","0.2.4","0.2.3","0.2.2","0.2.1","0.2.0","0.2.0M9","0.2.0M8","0.2.0M7","0.2.0M6","0.2.0M5","0.2.0M4","0.2.0M3","0.2.0M2","0.2.0M1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-27219.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}