CVE-2021-3152 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Information disclosure |
Description | Home Assistant before 2021.1.3 allows attackers to obtain sensitive information because custom integrations with ../ are mishandled leading to directory-traversal. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1488 | home-assistant | 2020.12.2-1 | 2021.1.4-1 | Medium | Fixed | FS#69398 |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
29 Jan 2021 | ASA-202101-44 | AVG-1488 | home-assistant | Medium | information disclosure |
References |
---|
https://www.home-assistant.io/blog/2021/01/14/security-bulletin/ |
Notes |
---|
Workaround ========== The issue can be mitigated by disabling all custom integrations. This is achieved by renaming the custom_components folder inside the Home Assistant configuration folder to something else and restarting Home Assistant. |