Executive brief
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py.
Affected products
- PyPI homeassistant
Junglewise Threat Intelligence
CVE-2018-21019 · Severity: low · CVSS 3.1 · Published 2019-09-23
Technologies: homeassistant (PyPI). Vendors: PyPI.
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py.