Safety vulnerability ID: 65199
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Home Assistant before version 2023.12.3 has a vulnerability where the login page would disclose all active user accounts to unauthenticated LAN requests. This aimed to simplify login by displaying user profiles, similar to other applications. However, it exposed accounts to any LAN-connected device. Version 2023.12.3 patches this issue, limiting account visibility to enhance security. This vulnerability was specific to requests from the local or any reachable private subnet.
Latest version: 2024.11.3
Open-source home automation platform running on Python 3.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application