Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vfj8-5pj7-2f9g: OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)

Summary

The login functionality contains a reflected cross-site scripting (XSS) vulnerability.

Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition

Impact

This issue may lead up to Remote Code Execution (RCE).

NOTE: The complete advisory with much more information is added as comment.

ghsa
#xss#vulnerability#nodejs#git#rce
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2024-43795

OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)

Moderate severity GitHub Reviewed Published Oct 2, 2024 in OpenC3/cosmos

Package

npm @openc3/tool-common (npm)

Affected versions

< 5.19.0

Summary

The login functionality contains a reflected cross-site scripting (XSS) vulnerability.

Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition

Impact

This issue may lead up to Remote Code Execution (RCE).

NOTE: The complete advisory with much more information is added as comment.

References

  • GHSA-vfj8-5pj7-2f9g
  • OpenC3/cosmos@762d7e0

Published to the GitHub Advisory Database

Oct 2, 2024

ghsa: Latest News

GHSA-r7rh-jww5-5fjr: Pomerium service account access token may grant unintended access to databroker API