CVE-2024-42468
Last modified
CVE-2024-42468 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the server can be requested via HTTP GET on the CometVisuServlet. This issue may lead to information disclosure. Users should upgrade to version 4.2.1 of the CometVisu add-on of openHAB to receive a patch.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openhab | Openhab | < 4.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-42468?
How severe is CVE-2024-42468?
How do I fix CVE-2024-42468?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-42462Improper Authentication vulnerability in upKeeper Solutions …9.8
- CVE-2024-42463Authorization Bypass Through User-Controlled Key vulnerabili…6.5
- CVE-2024-42464Authorization Bypass Through User-Controlled Key vulnerabili…6.5
- CVE-2024-42465Improper Restriction of Excessive Authentication Attempts vu…9.8
- CVE-2024-42466Improper Restriction of Excessive Authentication Attempts vu…9.8
- CVE-2024-42467openHAB, a provider of open-source home automation software,…10
- CVE-2024-42469openHAB, a provider of open-source home automation software,…9.8
- CVE-2024-4247A vulnerability has been found in Tenda i21 1.0.0.14(4656) a…8.8
- CVE-2024-42470openHAB, a provider of open-source home automation software,…9.1
- CVE-2024-42471actions/artifact is the GitHub ToolKit for developing GitHub…7.5
- CVE-2024-42472Flatpak is a Linux application sandboxing and distribution f…10
- CVE-2024-42473OpenFGA is an authorization/permission engine. OpenFGA v1.5.…9.8
Are you affected by CVE-2024-42468?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
