Org.openhab.ui.bundles:org.openhab.ui.cometvisu: CometVisu Backend for openHAB affected by SSRF/XSS (CVE-2024-42467)
The [proxy endpoint](https://github.com/openhab/openhab-webui/blob/1c03c60f84388b9d7da0231df2d4ebb1e17d3fcf/bundles/org.openhab.ui.cometvisu/src/main/java/org/openhab/ui/cometvisu/internal/backend/rest/ProxyResource.java#L83) of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can be exploited as Server-Side Request Forgery (SSRF) to induce GET HTTP requests to internal-only servers, in case openHAB is exposed in a non-private network. Furthermore, this proxy-feature can also be exploited as a Cross-Site Scripting (XSS) vulnerability, as an attacker is able to re-route a request to their server and return a page with malicious JavaScript code. Since the browser receives this data directly from the openHAB CometVisu UI, this JavaScript code will be executed with the origin of the CometVisu UI. This allows an attacker to exploit call endpoints on an openHAB server even if the openHAB server is located in a private network. (e.g. by sending an openHAB admin a link that proxies malicious JavaScript.) This vulnerability was discovered with the help of CodeQL's [Server-side request forgery](https://codeql.github.com/codeql-query-help/java/java-ssrf/) query. ## Impact This issue may lead up to Remote Code Execution (RCE) when chained with other vulnerabilities (see: GHSL-2024-007).
AI Analysis
Technical Summary
The openHAB CometVisu add-on's proxy endpoint is unauthenticated and vulnerable to SSRF, allowing attackers to induce GET requests to internal-only servers when openHAB is exposed externally. It also allows XSS attacks by enabling attackers to serve malicious JavaScript through the proxy, executing with the UI's origin. This can be leveraged to call endpoints on openHAB servers even within private networks. The vulnerability was identified using CodeQL SSRF queries and is tracked as CVE-2024-42467 with a critical CVSS 3.1 score of 10. The issue may lead to Remote Code Execution if chained with other vulnerabilities such as GHSL-2024-007. A patch is available to remediate this vulnerability.
Potential Impact
Successful exploitation can allow attackers to perform SSRF attacks, accessing internal network resources not normally reachable externally. The XSS vulnerability enables execution of arbitrary JavaScript in the context of the CometVisu UI, potentially allowing attackers to interact with the openHAB server as if they were authorized users. This can lead to further compromise, including Remote Code Execution when combined with other vulnerabilities.
Mitigation Recommendations
A patch is available for this vulnerability and should be applied promptly. Since the proxy endpoint is unauthenticated and exploitable, upgrading to the fixed version of the CometVisu add-on is the recommended remediation. No vendor advisory content contradicts this; therefore, patching is the primary mitigation.
Org.openhab.ui.bundles:org.openhab.ui.cometvisu: CometVisu Backend for openHAB affected by SSRF/XSS (CVE-2024-42467)
Description
The [proxy endpoint](https://github.com/openhab/openhab-webui/blob/1c03c60f84388b9d7da0231df2d4ebb1e17d3fcf/bundles/org.openhab.ui.cometvisu/src/main/java/org/openhab/ui/cometvisu/internal/backend/rest/ProxyResource.java#L83) of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can be exploited as Server-Side Request Forgery (SSRF) to induce GET HTTP requests to internal-only servers, in case openHAB is exposed in a non-private network. Furthermore, this proxy-feature can also be exploited as a Cross-Site Scripting (XSS) vulnerability, as an attacker is able to re-route a request to their server and return a page with malicious JavaScript code. Since the browser receives this data directly from the openHAB CometVisu UI, this JavaScript code will be executed with the origin of the CometVisu UI. This allows an attacker to exploit call endpoints on an openHAB server even if the openHAB server is located in a private network. (e.g. by sending an openHAB admin a link that proxies malicious JavaScript.) This vulnerability was discovered with the help of CodeQL's [Server-side request forgery](https://codeql.github.com/codeql-query-help/java/java-ssrf/) query. ## Impact This issue may lead up to Remote Code Execution (RCE) when chained with other vulnerabilities (see: GHSL-2024-007).
CVSS v3.1
Score 10.0critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The openHAB CometVisu add-on's proxy endpoint is unauthenticated and vulnerable to SSRF, allowing attackers to induce GET requests to internal-only servers when openHAB is exposed externally. It also allows XSS attacks by enabling attackers to serve malicious JavaScript through the proxy, executing with the UI's origin. This can be leveraged to call endpoints on openHAB servers even within private networks. The vulnerability was identified using CodeQL SSRF queries and is tracked as CVE-2024-42467 with a critical CVSS 3.1 score of 10. The issue may lead to Remote Code Execution if chained with other vulnerabilities such as GHSL-2024-007. A patch is available to remediate this vulnerability.
Potential Impact
Successful exploitation can allow attackers to perform SSRF attacks, accessing internal network resources not normally reachable externally. The XSS vulnerability enables execution of arbitrary JavaScript in the context of the CometVisu UI, potentially allowing attackers to interact with the openHAB server as if they were authorized users. This can lead to further compromise, including Remote Code Execution when combined with other vulnerabilities.
Mitigation Recommendations
A patch is available for this vulnerability and should be applied promptly. Since the proxy endpoint is unauthenticated and exploitable, upgrading to the fixed version of the CometVisu add-on is the recommended remediation. No vendor advisory content contradicts this; therefore, patching is the primary mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v7gr-mqpj-wwh3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2024-42467"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a73572cbf8831d53913cb06
Added to database: 08/05/2026, 15:30:52 UTC
Last enriched: 08/05/2026, 15:32:03 UTC
Last updated: 08/13/2026, 12:41:03 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.