Safety vulnerability ID: 63183
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Homeassistant 2023.9.0 includes a fix for CVE-2023-41899: In affected versions the 'hassio.addon_stdin' is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able to invoke any Supervisor REST API endpoints with a POST request. An attacker able to exploit will be able to control the data dictionary, including its addon and input key/values.
https://github.com/home-assistant/core/pull/99232
Latest version: 2024.11.3
Open-source home automation platform running on Python 3.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application