Aller au contenu

Fiche vulnérabilité

CVE-2024-42468 : faille élevée openhab openhab (CVSS 7.5)

Description

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the server can be requested via HTTP GET on the CometVisuServlet. This issue may lead to information disclosure. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
12 août 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • openhab openhab

Références

Rechercher une autre vulnérabilité dans la base CVE