A remotely exploitable vulnerability in the Home Assistant platform

A critical vulnerability (CVE-2023-27482) has been discovered in the open home automation platform Home Assistant, allowing authentication bypass and full access to the privileged Supervisor API, through which settings can be changed, software can be installed/updated, and add-ons and backups can be managed.

The issue affects installations using the Supervisor component and has been present since its early releases (since 2017). For example, the vulnerability exists in Home Assistant OS and Home Assistant Supervised environments, but does not affect Home Assistant Container (Docker) or manually created Python environments based on Home Assistant Core.

The vulnerability has been fixed in version Home Assistant Supervisor 2023.01.1. Additionally, a workaround has been included in the Home Assistant 2023.3.0 release. On systems where updating to block the vulnerability is not possible, access to the Home Assistant web service network port can be restricted from external networks.

The method of exploiting the vulnerability is not detailed yet (developers estimate that about 1/3 of users have installed the update, and many systems remain vulnerable). The corrected version includes changes in token handling and proxied requests under the guise of optimization, as well as added filters to block SQL query substitutions, insertion of the <script> tag, and the use of paths with "..\/" and "\/.",

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster