Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-50715

Опубликовано: 15 дек. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch for this issue.

When starting the Home Assistant 2023.12 release, the login page returns all currently active user accounts to browsing requests from the Local Area Network. Tests showed that this occurs when the request is not authenticated and the request originated locally, meaning on the Home Assistant host local subnet or any other private subnet. The rationale behind this is to make the login more user-friendly and an experience better aligned with other applications that have multiple user-profiles.

However, as a result, all accounts are displayed regardless of them having logged in or not and for any device that navigates to the server. This disclosure is mitigated by the fact that it only occurs for requests originating from a LAN

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*
Версия до 2023.12.3 (исключая)

EPSS

Процентиль: 37%
0.00153
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
около 2 лет назад

User accounts disclosed to unauthenticated actors on the LAN

EPSS

Процентиль: 37%
0.00153
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo