PT-2024-29964 · Cometvisu+1 · Cometvisu+1

P-

·

Published

2024-08-09

·

Updated

2024-09-12

·

CVE-2024-42468

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openHAB CometVisu add-on versions prior to 4.2.1
Description The CometVisuServlet in openHAB's CometVisu add-on is susceptible to an unauthenticated path traversal vulnerability. This issue allows local files on the server to be requested via HTTP GET on the CometVisuServlet, potentially leading to information disclosure.
Recommendations For openHAB CometVisu add-on versions prior to 4.2.1, upgrade to version 4.2.1 to receive a patch. As a temporary workaround, consider restricting access to the CometVisuServlet to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-42468
GHSA-PCWP-26PW-J98W

Affected Products

Cometvisu
Openhab