← volver
CVE-2023-41897

Lack of XFO header allows clickjacking in Home Assistant Core

CVSS 8.8 HIGHEPSS 0.9%CWE-1021
En resumen

Home Assistant no impide que su interfaz sea incrustada en sitios web falsos, permitiendo que atacantes engañen a usuarios para hacer clic en botones que instalan complementos maliciosos y toman control de su sistema de automatización del hogar.

Detalle técnico

La ausencia de headers X-Frame-Options y correlatos permite ataques de clickjacking donde un atacante incrusta Home Assistant en un iframe en un sitio malicioso, engañando a usuarios para que otorguen permisos o instalen complementos no autorizados que ejecutan código arbitrario dentro del contexto de la aplicación.

Resumen generado y traducido por IA a partir de la descripción oficial.
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative exploit opportunities, such as the vector described in this security advisory. This fault incurs major risk, considering the ability to trick users into installing an external and malicious add-on with minimal user interaction, which would enable Remote Code Execution (RCE) within the Home Assistant application. This issue has been addressed in version 2023.9.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
home-assistant · core

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →