Authentication bypass: PIN validation fails to reject incorrect PINs #22

Closed
opened 2025-11-13 11:47:44 -06:00 by GiteaMirror · 3 comments
Owner

Originally created by @mallendeo on GitHub (Jan 18, 2025).

I assigned an access PIN to my HomeAssistant instance, but when entering any PIN code, the system grants access regardless of whether the PIN is correct or not.

This does not happen when using only the password method though.

Image

Enabling PIN makes it insecure.

Originally created by @mallendeo on GitHub (Jan 18, 2025). I assigned an access PIN to my HomeAssistant instance, but when entering any PIN code, the system grants access regardless of whether the PIN is correct or not. This does not happen when using only the password method though. <img width="568" alt="Image" src="https://github.com/user-attachments/assets/1ece650c-fd55-4b15-8542-09b7da5adb55" /> Enabling PIN makes it insecure.
Author
Owner

@miloschwartz commented on GitHub (Jan 18, 2025):

Annnnnd this is why we're in beta. Thank you for finding the fix and opening the PR so quickly!

I just merged the PR and published 1.0.0-beta.7 for you to update to. In the future please send any security issues to me privately as per the security policy.

Thanks again!

@miloschwartz commented on GitHub (Jan 18, 2025): Annnnnd this is why we're in beta. Thank you for finding the fix and opening the PR so quickly! I just merged the PR and published 1.0.0-beta.7 for you to update to. In the future please send any security issues to me privately as per the security policy. Thanks again!
Author
Owner

@mallendeo commented on GitHub (Jan 18, 2025):

Thanks for the quick merge!

Just spotted the SECURITY.md after the fact, my bad 😬.
Will keep that in mind for next time.

@mallendeo commented on GitHub (Jan 18, 2025): Thanks for the quick merge! Just spotted the SECURITY.md after the fact, my bad 😬. Will keep that in mind for next time.
Author
Owner

@miloschwartz commented on GitHub (Jan 18, 2025):

Thanks for the quick merge!

Just spotted the SECURITY.md after the fact, my bad 😬. Will keep that in mind for next time.

No worries!

@miloschwartz commented on GitHub (Jan 18, 2025): > Thanks for the quick merge! > > Just spotted the SECURITY.md after the fact, my bad 😬. Will keep that in mind for next time. No worries!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/pangolin#22