Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-41893

Опубликовано: 20 окт. 2023
Источник: nvd
CVSS3: 4.3
CVSS3: 5.4
EPSS Низкий

Описание

Home assistant is an open source home automation. The audit team’s analyses confirmed that the redirect_uri and client_id are alterable when logging in. Consequently, the code parameter utilized to fetch the access_token post-authentication will be sent to the URL specified in the aforementioned parameters. Since an arbitrary URL is permitted and homeassistant.local represents the preferred, default domain likely used and trusted by many users, an attacker could leverage this weakness to manipulate a user and retrieve account access. Notably, this attack strategy is plausible if the victim has exposed their Home Assistant to the Internet, since after acquiring the victim’s access_token the adversary would need to utilize it directly towards the instance to achieve any pertinent malicious actions. To achieve this compromise attempt, the attacker must send a link with a redirect_uri that they control to the victim’s own Home Assistant instance. In the eventuality the vi

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*
Версия до 2023.9.0 (исключая)

EPSS

Процентиль: 49%
0.00262
Низкий

4.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

Home Assistant vulnerable to account takeover via auth_callback login

EPSS

Процентиль: 49%
0.00262
Низкий

4.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo