CVE-2021-3152 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
Home Assistant before 2021.1.3 allows attackers to obtain sensitive information because custom integrations with ../ are mishandled leading to directory-traversal.
Group Package Affected Fixed Severity Status Ticket
AVG-1488 home-assistant 2020.12.2-1 2021.1.4-1 Medium Fixed FS#69398
Date Advisory Group Package Severity Type
29 Jan 2021 ASA-202101-44 AVG-1488 home-assistant Medium information disclosure
References
https://www.home-assistant.io/blog/2021/01/14/security-bulletin/
Notes
Workaround
==========

The issue can be mitigated by disabling all custom integrations. This is achieved by renaming the custom_components folder inside the Home Assistant configuration folder to something else and restarting Home Assistant.