Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3152

Опубликовано: 26 янв. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*
Версия до 2021.1.3 (исключая)

EPSS

Процентиль: 60%
0.00404
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

** DISPUTED ** Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation.

EPSS

Процентиль: 60%
0.00404
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22