CVE-2021-3152
Home Assistant HACS - Local File Inclusion
Record summary
CVE-2021-3152 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHHome Assistant HACS - Local File InclusionCVSS 7.5
Home Assistant before 2021.1.3 lacks a protection layer against directory-traversal attacks in custom integrations, letting attackers access arbitrary files, exploit requires attacker to deploy malicious custom integration.
Impact
Attackers can access sensitive files on the system, potentially leading to information disclosure or further system compromise.
Remediation
Update to version 2021.1.3 or later to include protection against directory traversal in custom integrations.
Source: ProjectDiscovery