openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the server can be requested via HTTP GET on the CometVisuServlet. This issue may lead to information disclosure. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openhab openhab
|
|
CPEs | cpe:2.3:a:openhab:openhab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openhab openhab
|
Tue, 13 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openhab
Openhab openhab Webui |
|
CPEs | cpe:2.3:a:openhab:openhab_webui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openhab
Openhab openhab Webui |
|
Metrics |
ssvc
|
Fri, 09 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the server can be requested via HTTP GET on the CometVisuServlet. This issue may lead to information disclosure. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch. | |
Title | Path traversal (CometVisu) | |
Weaknesses | CWE-22 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-09T18:10:20.660Z
Updated: 2024-08-13T18:39:57.323Z
Reserved: 2024-08-02T14:13:04.614Z
Link: CVE-2024-42468
Vulnrichment
Updated: 2024-08-13T18:39:53.666Z
NVD
Status : Analyzed
Published: 2024-08-12T13:38:34.970
Modified: 2024-09-12T16:01:42.113
Link: CVE-2024-42468
Redhat
No data.