CVE-2017-16782: XSS
Withdrawn Advisory This advisory has been withdrawn because we cannot confirm home-assistant-frontend is or was ever published to npm.
Original Description In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-16782?
CVE-2017-16782 is a vulnerability that allows an attacker to inject JavaScript code into a persistent notification in Home Assistant before version 0.57.
How severe is CVE-2017-16782?
CVE-2017-16782 has a severity rating of medium.
Which software versions are affected by CVE-2017-16782?
CVE-2017-16782 affects Home Assistant versions up to and including 0.56.2 and Home-assistant-frontend version up to and excluding 0.57.
How can an attacker exploit CVE-2017-16782?
An attacker can exploit CVE-2017-16782 by injecting JavaScript code into a persistent notification in Home Assistant.
Is there a fix for CVE-2017-16782?
Yes, the fix for CVE-2017-16782 is to update Home Assistant to version 0.57 or later.