Headline
GHSA-vfj8-5pj7-2f9g: OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Summary
The login functionality contains a reflected cross-site scripting (XSS) vulnerability.
Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition
Impact
This issue may lead up to Remote Code Execution (RCE).
NOTE: The complete advisory with much more information is added as comment.
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2024-43795
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Moderate severity GitHub Reviewed Published Oct 2, 2024 in OpenC3/cosmos
Package
npm @openc3/tool-common (npm)
Affected versions
< 5.19.0
Summary
The login functionality contains a reflected cross-site scripting (XSS) vulnerability.
Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition
Impact
This issue may lead up to Remote Code Execution (RCE).
NOTE: The complete advisory with much more information is added as comment.
References
- GHSA-vfj8-5pj7-2f9g
- OpenC3/cosmos@762d7e0
Published to the GitHub Advisory Database
Oct 2, 2024