CVE-2018-21019: Infoleak
Published Sep 23, 2019
·Updated
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py.
Affected Software
2 affected componentsFixes available
pip/homeassistant<0.67.0
0.67.0
home-assistant home-assistant<0.67.0
Remediation
Patch Available
Event History
Sep 23, 2019
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
Description
May 24, 2022
Advisory Published
via GitHub·04:56 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-21019.
2
What is the severity level of CVE-2018-21019?
The severity level of CVE-2018-21019 is high.
3
How does CVE-2018-21019 affect Home Assistant?
CVE-2018-21019 affects Home Assistant version 0.67.0 and earlier versions.
4
What is the impact of CVE-2018-21019?
CVE-2018-21019 allows an unauthenticated attacker to read the application's error log in Home Assistant.
5
How can I fix CVE-2018-21019?
To fix CVE-2018-21019, update Home Assistant to version 0.67.0 or later.