KUKSA.val是Eclipse基金会的一个面向车载数据访问与通信的中间件组件。 KUKSA.val存在访问控制错误漏洞,该漏洞源于仅持有读取JWT范围的客户端仍可通过OpenProviderStream API注册为信号提供者,可能导致攻击者向其他客户端提供伪造数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse KUKSA - Databroker | 0.5.0 ~ 0.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet