The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in their Home Assistant installation. Combined with this security advisory, may result in full compromise and remote code execution (RCE). Version 2023.7 addresses this issue and all users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as GitHub Security Lab (GHSL) Vulnerability Report: GHSL-2023-161.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-10-19T22:02:52.674Z

Updated: 2024-09-12T15:13:30.561Z

Reserved: 2023-09-28T17:56:32.613Z

Link: CVE-2023-44385

cve-icon Vulnrichment

Updated: 2024-08-02T20:07:32.887Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-19T23:15:08.953

Modified: 2023-10-26T15:52:54.817

Link: CVE-2023-44385

cve-icon Redhat

No data.