SCA: security update for homeassistant (GHSA-jqpc-rc7g-vf83)

medium Tenable Cloud Security Plugin ID 416537

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page
discloses all active user accounts to any unauthenticated browsing request originating on the Local Area
Network. Version 2023.12.3 contains a patch for this issue. When starting the Home Assistant 2023.12
release, the login page returns all currently active user accounts to browsing requests from the Local
Area Network. Tests showed that this occurs when the request is not authenticated and the request
originated locally, meaning on the Home Assistant host local subnet or any other private subnet. The
rationale behind this is to make the login more user-friendly and an experience better aligned with other
applications that have multiple user-profiles. However, as a result, all accounts are displayed regardless
of them having logged in or not and for any device that navigates to the server. This disclosure is
mitigated by the fact that it only occurs for requests originating from a LAN address. But note that this
applies to the local subnet where Home Assistant resides and to any private subnet that can reach it.
(CVE-2023-50715)

See Also

https://github.com/advisories/GHSA-jqpc-rc7g-vf83

Plugin Details

Severity: Medium

ID: 416537

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.6

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2023-50715

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.9

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/15/2023

Vulnerability Publication Date: 12/15/2023

Reference Information

CVE: CVE-2023-50715

cwe: CWE-200