Related Vulnerabilities: CVE-2021-3152  

Home Assistant before 2021.1.3 allows attackers to obtain sensitive information because custom integrations with ../ are mishandled.

Severity Medium

Remote Yes

Type Information disclosure

Description

Home Assistant before 2021.1.3 allows attackers to obtain sensitive information because custom integrations with ../ are mishandled.

AVG-1488 home-assistant 2020.12.2-1 2021.1.4-1 Medium Fixed FS#69398

https://www.home-assistant.io/blog/2021/01/14/security-bulletin/

Workaround
==========

The issue can be mitigated by disabling all custom integrations. This is achieved by renaming the custom_components folder inside the Home Assistant configuration folder to something else and restarting Home Assistant.