In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10243.json"