CVE-2020-36517

An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
References
Link Resource
https://community.home-assistant.io/t/ha-os-dns-setting-configuration-not-respected/356572 Exploit Issue Tracking Vendor Advisory
https://github.com/home-assistant/plugin-dns/issues/17 Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/20 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/22 Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/50 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/51 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/53 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/54 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/6 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/64 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/70 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/55 Exploit Patch Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/56 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/58 Patch Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/59 Issue Tracking Patch Third Party Advisory
https://community.home-assistant.io/t/ha-os-dns-setting-configuration-not-respected/356572 Exploit Issue Tracking Vendor Advisory
https://github.com/home-assistant/plugin-dns/issues/17 Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/20 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/22 Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/50 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/51 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/53 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/54 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/6 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/64 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/70 Exploit Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/55 Exploit Patch Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/56 Exploit Issue Tracking Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/58 Patch Third Party Advisory
https://github.com/home-assistant/plugin-dns/pull/59 Issue Tracking Patch Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:home-assistant:home-assistant:2022.03:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-03-10 17:41

Updated : 2024-11-21 05:29


NVD link : CVE-2020-36517

Mitre link : CVE-2020-36517

CVE.ORG link : CVE-2020-36517


JSON object : View

Products Affected

home-assistant

  • home-assistant
CWE
CWE-203

Observable Discrepancy