Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-pcwp-26pw-j98w: CometVisu Backend for openHAB has a path traversal vulnerability

openHAB’s CometVisuServlet is susceptible to an unauthenticated path traversal vulnerability.

Local files on the server can be requested via HTTP GET on the CometVisuServlet.

This vulnerability was discovered with the help of CodeQL’s Uncontrolled data used in path expression query.

Impact

This issue may lead to Information Disclosure.

ghsa
#vulnerability#web#git#java#auth

CometVisu Backend for openHAB has a path traversal vulnerability

Moderate severity GitHub Reviewed Published Aug 9, 2024 in openhab/openhab-webui • Updated Aug 9, 2024

ghsa: Latest News

GHSA-27wf-5967-98gx: Kubernetes kubelet arbitrary command execution