CometVisu Backend for openHAB has a path traversal vulnerability
Moderate severity
GitHub Reviewed
Published
Aug 9, 2024
in
openhab/openhab-webui
•
Updated Aug 12, 2024
Package
Affected versions
<= 4.2.0
Patched versions
4.2.1
Description
Published to the GitHub Advisory Database
Aug 9, 2024
Reviewed
Aug 9, 2024
Published by the National Vulnerability Database
Aug 12, 2024
Last updated
Aug 12, 2024
openHAB's CometVisuServlet is susceptible to an unauthenticated path traversal vulnerability.
Local files on the server can be requested via HTTP GET on the CometVisuServlet.
This vulnerability was discovered with the help of CodeQL's Uncontrolled data used in path expression query.
Impact
This issue may lead to Information Disclosure.
References