openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the server can be requested via HTTP GET on the CometVisuServlet. This issue may lead to information disclosure. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2625 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the server can be requested via HTTP GET on the CometVisuServlet. This issue may lead to information disclosure. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch. |
Github GHSA |
GHSA-pcwp-26pw-j98w | CometVisu Backend for openHAB has a path traversal vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openhab openhab
|
|
| CPEs | cpe:2.3:a:openhab:openhab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openhab openhab
|
Tue, 13 Aug 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openhab
Openhab openhab Webui |
|
| CPEs | cpe:2.3:a:openhab:openhab_webui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openhab
Openhab openhab Webui |
|
| Metrics |
ssvc
|
Fri, 09 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the server can be requested via HTTP GET on the CometVisuServlet. This issue may lead to information disclosure. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch. | |
| Title | Path traversal (CometVisu) | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-13T18:39:57.323Z
Reserved: 2024-08-02T14:13:04.614Z
Link: CVE-2024-42468
Updated: 2024-08-13T18:39:53.666Z
Status : Analyzed
Published: 2024-08-12T13:38:34.970
Modified: 2024-09-12T16:01:42.113
Link: CVE-2024-42468
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA