CVE-2021-3152: Path Traversal
DISPUTED Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Home Assistantto a version that resolves this vulnerability.Fixed in 2021.1.3
Event History
Frequently Asked Questions
What is CVE-2021-3152?
CVE-2021-3152 is a vulnerability in Home Assistant before version 2021.1.3 that allows directory-traversal attacks against custom integrations.
What is the severity of CVE-2021-3152?
CVE-2021-3152 has a severity level of medium with a CVSS score of 5.3.
How does CVE-2021-3152 affect Home Assistant?
CVE-2021-3152 affects Home Assistant versions up to and excluding 2021.1.3.
Are there any references for CVE-2021-3152?
Yes, you can refer to the following links for more information: [link1](https://www.home-assistant.io/blog/2021/01/14/security-bulletin/) and [link2](https://www.home-assistant.io/blog/2021/01/22/security-disclosure/).
What is the Common Weakness Enumeration (CWE) for CVE-2021-3152?
The Common Weakness Enumeration (CWE) for CVE-2021-3152 is CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').