Several endpoints in the CometVisu add-on of openHAB don't require authentication. This makes it possible for unauthenticated attackers to modify or to steal sensitive data.
This issue may lead to sensitive Information Disclosure.
{ "nvd_published_at": "2024-08-12T13:38:35Z", "cwe_ids": [ "CWE-862" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-08-09T18:21:22Z" }