- EPSS 0.01%
- Veröffentlicht 23.12.2025 00:00:00
- Zuletzt bearbeitet 06.01.2026 17:27:46
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
CVE-2023-50715
- EPSS 0.21%
- Veröffentlicht 15.12.2023 03:15:45
- Zuletzt bearbeitet 21.11.2024 08:37:11
Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch fo...
CVE-2023-41893
- EPSS 0.26%
- Veröffentlicht 20.10.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication wil...
CVE-2023-41894
- EPSS 0.19%
- Veröffentlicht 20.10.2023 00:15:16
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from th...
CVE-2023-41895
- EPSS 0.51%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redir...
- EPSS 0.2%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The s...
CVE-2023-41897
- EPSS 1.88%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:52
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating h...
CVE-2023-41899
- EPSS 0.16%
- Veröffentlicht 19.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:53
Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able t...
- EPSS 88.57%
- Veröffentlicht 08.03.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:52:59
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that u...
CVE-2020-36517
- EPSS 1.85%
- Veröffentlicht 10.03.2022 17:41:21
- Zuletzt bearbeitet 21.11.2024 05:29:44
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.