Eclipse hawkBit是Eclipse基金会的一个软件更新管理平台。 Eclipse hawkBit 1.0.3及之前版本存在安全漏洞,该漏洞源于Direct Device Integration (DDI) Controller中存在对象级授权验证缺陷,允许已通过身份验证的设备权限提升,绕过更新分配边界,下载同一租户内的任意固件工件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | eclipse-hawkbit/hawkbit | ≤ 1.0.3 |
affected |
1.0.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | eclipse-hawkbit/hawkbit | 0 ~ 1.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16439 | Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow | |
| CVE-2026-16243 | Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compar | |
| CVE-2026-16441 | Eclipse OpenJ9 : Method resolution default method precedence failure |
No comments yet