CVE-2021-3152 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Information disclosure |
| Description | Home Assistant before 2021.1.3 allows attackers to obtain sensitive information because custom integrations with ../ are mishandled leading to directory-traversal. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1488 | home-assistant | 2020.12.2-1 | 2021.1.4-1 | Medium | Fixed | FS#69398 |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 29 Jan 2021 | ASA-202101-44 | AVG-1488 | home-assistant | Medium | information disclosure |
| References |
|---|
https://www.home-assistant.io/blog/2021/01/14/security-bulletin/ |
| Notes |
|---|
Workaround ========== The issue can be mitigated by disabling all custom integrations. This is achieved by renaming the custom_components folder inside the Home Assistant configuration folder to something else and restarting Home Assistant. |