Odkryto krytyczną podatność w Home Assistant Supervisor umożliwiającą zdalne ominięcie uwierzytelnienia (auth bypass) podczas dostępu do Supervisor API przez Home Assistant. Podatność otrzymała maksymalną ocenę CVSS 10.0, co oznacza pełne zagrożenie dla poufności, integralności i dostępności systemu.
▸ Pokaż oryginał (EN)
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected. The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet.
Atakujący zdalnie, bez uwierzytelnienia i bez interakcji użytkownika, może uzyskać dostęp do Supervisor API poprzez Home Assistant, omijając mechanizmy kontroli dostępu (CWE-287 — nieprawidłowe uwierzytelnienie). Podatność dotyczy wyłącznie instalacji korzystających z komponentu Supervisor w wersji 2023.01.1 lub starszej. Instalacje oparte na Home Assistant Container (np. Docker) oraz ręczne instalacje Home Assistant Core w środowisku Python nie są podatne.
Atakujący może uzyskać nieautoryzowany, pełny dostęp do Supervisor API, co potencjalnie prowadzi do przejęcia kontroli nad całą instancją Home Assistant, w tym odczytu danych konfiguracyjnych, modyfikacji ustawień oraz zakłócenia działania systemu automatyki domowej.
Należy zaktualizować Home Assistant Supervisor do wersji 2023.03.1 lub nowszej (poprawka została automatycznie wdrożona przez mechanizm auto-update Supervisora). Zalecana jest również aktualizacja Home Assistant Core do wersji 2023.3.0 lub nowszej, która zawiera dodatkowe zabezpieczenia przed tą podatnością. Jeśli aktualizacja nie jest możliwa, należy niezwłocznie odizolować instancję Home Assistant od internetu (nie eksponować jej publicznie).
Wszystkie typy instalacji Home Assistant wykorzystujące komponent Supervisor w wersji 2023.01.1 lub starszej. Instalacje Home Assistant Container (Docker) oraz Home Assistant Core zainstalowany ręcznie w środowisku Python NIE są podatne.
Producent potwierdził, że aktualizacja Supervisora do wersji 2023.03.1 została automatycznie rozesłana do wszystkich podatnych instalacji przed datą publikacji biuletynu (2023-03-08). Szczegółowy writeup techniczny podatności opublikowała firma elttam (referencje wskazują na blog elttam.com oraz repozytorium GitHub elttam/publications).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHome Assistant
APPHome-Assistant< 2023.3.0Home Assistant Supervisor
APPHome-Assistant< 2023.03.1
Powiązane podatności
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 202...
Home Assistant is open source home automation software that puts local control and privacy first. Starting in ...
Home Assistant is open source home automation software that puts local control and privacy first. Starting in ...
Home assistant is an open source home automation. The Home Assistant login page allows users to use their loca...
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden paramet...