CVE-2023-41899

Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able to invoke any Supervisor REST API endpoints with a POST request. An attacker able to exploit will be able to control the data dictionary, including its addon and input key/values. This issue has been addressed in version 2023.9.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as GitHub Security Lab (GHSL) Vulnerability Report: `GHSL-2023-162`.
Configurations

Configuration 1 (hide)

cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*

History

26 Oct 2023, 16:03

Type Values Removed Values Added
CPE cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*
First Time Home-assistant
Home-assistant home-assistant
CWE CWE-918
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
References (MISC) https://github.com/home-assistant/core/security/advisories/GHSA-h2jp-7grc-9xpp - (MISC) https://github.com/home-assistant/core/security/advisories/GHSA-h2jp-7grc-9xpp - Vendor Advisory
References (MISC) https://github.com/home-assistant/core/security/advisories/GHSA-4r74-h49q-rr3h - (MISC) https://github.com/home-assistant/core/security/advisories/GHSA-4r74-h49q-rr3h - Vendor Advisory

19 Oct 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-19 23:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-41899

Mitre link : CVE-2023-41899

CVE.ORG link : CVE-2023-41899


JSON object : View

Products Affected

home-assistant

  • home-assistant
CWE
CWE-918

Server-Side Request Forgery (SSRF)