CometVisu Backend for openHAB has a sensitive information disclosure vulnerability
Moderate severity
GitHub Reviewed
Published
Aug 9, 2024
in
openhab/openhab-webui
•
Updated Aug 12, 2024
Package
Affected versions
<= 4.2.0
Patched versions
4.2.1
Description
Published to the GitHub Advisory Database
Aug 9, 2024
Reviewed
Aug 9, 2024
Published by the National Vulnerability Database
Aug 12, 2024
Last updated
Aug 12, 2024
Several endpoints in the CometVisu add-on of openHAB don't require authentication. This makes it possible for unauthenticated attackers to modify or to steal sensitive data.
Impact
This issue may lead to sensitive Information Disclosure.
References