openHAB's CometVisuServlet is susceptible to an unauthenticated path traversal vulnerability.
Local files on the server can be requested via HTTP GET on the CometVisuServlet.
This vulnerability was discovered with the help of CodeQL's Uncontrolled data used in path expression query.
This issue may lead to Information Disclosure.
| Score | Percentile |
|---|---|
| 1.55% | 80.99% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 5.3 | 3.1 | — |
|
| 6.9 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-pcwp-26pw-j98w ↗ |
| CVE | CVE-2024-42468 ↗ |
| CWE id | Name |
|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| maven | org.openhab.ui.bundles:org.openhab.ui.cometvisu | <= 4.2.0 | 4.2.1 | — |