openHAB是openHAB开源的一款家庭自动化应用程序。 openHAB 4.2.1之前版本存在安全漏洞,该漏洞源于无需身份验证即可访问附加组件的代理端点,在非私有网络中,此代理功能可用作服务器请求伪造,以诱导对内部服务器的GET HTTP请求。此代理还可用作跨站脚本攻击,即使服务器位于私有网络中,仍允许攻击者利用服务器上的调用端点。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| openhab | openhab-webui | >= 3.4.0.M4, < 4.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openhab | openhab-webui | >= 3.4.0.M4, < 4.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-42469 | 9.8 CRITICAL | CometVisu Backend for openHAB affected by RCE through path traversal |
| CVE-2024-42470 | 6.5 MEDIUM | CometVisu Backend for openHAB has a sensitive information disclosure vulnerability |
| CVE-2024-42468 | 5.3 MEDIUM | Path traversal (CometVisu) |
No comments yet