Junglewise Threat Intelligence

CVE-2024-42467: openHAB CometVisu SSRF and XSS in ProxyResource

CVE-2024-42467 · Severity: critical · CVSS 10 · Published 2024-08-09

Technologies: org.openhab.ui.bundles:org.openhab.ui.cometvisu (Maven). Vendors: Maven.

Executive brief

The CometVisu add-on for openHAB, a popular home automation platform, contains a security flaw in its proxy feature. An attacker can use this to access internal network services or trick administrators into executing malicious code. This could lead to unauthorized control over the smart home system or the theft of sensitive configuration data.

Technical details

The ProxyResource.java component in the CometVisu backend fails to implement authentication or proper validation on its proxy endpoint. This allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) by inducing GET requests to internal-only servers. Additionally, the endpoint is vulnerable to Cross-Site Scripting (XSS) because it can be forced to fetch and serve malicious JavaScript from an attacker-controlled server, which then executes in the context of the CometVisu UI origin. When chained with other vulnerabilities, this can lead to Remote Code Execution (RCE). The issue is fixed in version 4.2.1.

Affected products

  • openHAB openHAB CometVisu UI >= 3.4.0.M4, <= 4.2.0

Timeline

  • 2024-08-09: advisory: GHSA-v7gr-mqpj-wwh3 published
  • 2024-08-09: patched: Fix released in version 4.2.1
  • 2024-08-12: disclosed: CVE-2024-42467 assigned

References

Related threats