Intelligence View
CVE-2021-47942 | Home-Assistant Home Assistant Community Store up to 1.9.x Refresh Token /hacsfiles/ path traversal (Exploit 49495 / EUVD-2021-34838)
A vulnerability categorized as critical has been discovered in Home-Assistant Home Assistant Community Store up to 1.9.x. Impacted is an unknown function of the file /hacsfiles/ of the component Refresh Token Handler. Such manipulation…
This vulnerability is listed as CVE-2021-47942. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to upgrade the affected component.
2. Cyber Threat Intelligence & Forensik
3. Compliance, SLA & Vendor Adherence
Hersteller-Sicherheitsmeldungen & Patch-Status
Öffentliche PoCs existieren. Isolieren Sie das System oder wenden Sie Micro-Segmentierungsregeln an, bis offizielle Patches vorliegen.
-
Web Referencewww.home-assistant.io
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com