Popis
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment next to that line says auth is instead handled -via the access token from configuration.- That promise is only half true. Write requests (POST and PUT) are handled by update_sensor(), which does check the request-s Authorization: Bearer <token> header against the integration-s stored access tokens (using hmac.compare_digest). Read requests (GET) are handled by a separate get() method that has no authentication check at all. This vulnerability is fixed in 2026.6.0.
- Zverejnené
- 2026-06-23 18:18:08
- Dotknuté verzie
- <2026.6.0
- Typ
- Kritický softvér
- Vektor
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L