Log

CVE-2021-3152 edited at 29 Jan 2021 16:39:06
Description
- Home Assistant before 2021.1.3 allows attackers to obtain sensitive information because custom integrations with ../ are mishandled.
+ Home Assistant before 2021.1.3 allows attackers to obtain sensitive information because custom integrations with ../ are mishandled leading to directory-traversal.
ASA-202101-44 edited at 29 Jan 2021 16:38:37
Impact
- Some plugins could allow malicious users to read sensitive information.
+ Some integrations could allow malicious users to read sensitive information.
ASA-202101-44 edited at 29 Jan 2021 16:38:24
Workaround
+ The issue can be mitigated by disabling all custom integrations. This is achieved by renaming the custom_components folder inside the Home Assistant configuration folder to something else and restarting Home Assistant.
ASA-202101-44 edited at 29 Jan 2021 16:33:52
Impact
+ Some plugins could allow malicious users to read sensitive information.
ASA-202101-43 edited at 29 Jan 2021 16:33:28
Impact
+ A malicious user could send a malformed email that would crash the application.
ASA-202101-42 edited at 29 Jan 2021 16:33:03
Impact
+ A malicious user could query the API in a way that could result in a code execution flaw.
ASA-202101-45 edited at 29 Jan 2021 16:30:47
Impact
+ An attacker is able to execute arbitrary code on the affected host before a given signature has been verified.
ASA-202101-45 created at 29 Jan 2021 16:26:41
ASA-202101-44 created at 29 Jan 2021 16:26:36
ASA-202101-43 created at 29 Jan 2021 16:26:28