Vulnerabilities > Eclipse > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-27 CVE-2018-12536 In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using.
network
low complexity
eclipse oracle
5.3
2018-06-05 CVE-2017-7653 Improper Input Validation vulnerability in multiple products
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8.
network
high complexity
eclipse debian CWE-20
5.3
2017-09-11 CVE-2017-7650 Improper Authentication vulnerability in multiple products
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'.
network
low complexity
eclipse debian CWE-287
6.5
2017-06-25 CVE-2017-9868 Information Exposure vulnerability in multiple products
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
local
low complexity
eclipse debian CWE-200
5.5