Skip to content

Path traversal (CometVisu)

Moderate
kaikreuzer published GHSA-pcwp-26pw-j98w Aug 9, 2024

Package

maven org.openhab.ui.cometvisu (Maven)

Affected versions

<=4.2.0

Patched versions

4.2.1

Description

openHAB's CometVisuServlet is susceptible to an unauthenticated path traversal vulnerability.

Local files on the server can be requested via HTTP GET on the CometVisuServlet.

This vulnerability was discovered with the help of CodeQL's Uncontrolled data used in path expression query.

Impact

This issue may lead to Information Disclosure.

Severity

Moderate

CVE ID

CVE-2024-42468

Weaknesses

No CWEs

Credits