Write up from last years security update

Hello,

I am the security researcher who report the issue described in the notice here.

A write up of what was found and how it could have been exploited is now available.

https://ostrichlab.io/research-blog/?post=hubitat_writeup

If you haven't updated to at least 2.4.2.157, please do so now!

I do want to thanks @bobbyD and @gopher.ny for being quick and professional.

13 Likes

As long as I don't have to do any training because I missed a test spam email... :wink: That I should have picked up....

And thankyou btw... for taking the time to report and follow up on the risk you identified...

4 Likes

+1 thank you, and also thank you for interacting with the Hubitat team and empowering them to make a fix before further disclosure!

5 Likes