—
PYSEC-2021-351
Quick fix
PYSEC-2021-351 — esphome: upgrade to the fixed version with the command below.
pip install --upgrade 'esphome>=2234f6aacf8cc653307fed80f3750317a82c4f83'Details
ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username & password. This issue is patched in version 2021.9.2. As a workaround, one may disable or remove `web_server`.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/esphome
Introduced in:
0Fixed in: 2234f6aacf8cc653307fed80f3750317a82c4f83Fix
pip install --upgrade 'esphome>=2234f6aacf8cc653307fed80f3750317a82c4f83'References
- https://github.com/esphome/esphome/commit/2234f6aacf8cc653307fed80f3750317a82c4f83[FIX]
- https://github.com/esphome/esphome/pull/2409/commits/207cde1667d8c799a197b78ca8a5a14de8d5ca1e[WEB]
- https://github.com/esphome/esphome/releases/tag/2021.9.2[WEB]
- https://github.com/esphome/esphome/security/advisories/GHSA-48mj-p7x2-5jfm[ADVISORY]