MEDIUM6.5
GHSA-4g88-4hgm-m99x
NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability
Quick fix
GHSA-4g88-4hgm-m99x — openmct: upgrade to the fixed version with the command below.
npm install openmct@3.1.1Details
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-45884[ADVISORY]
- https://github.com/nasa/openmct/pull/7148[WEB]
- https://github.com/nasa/openmct/pull/7148/commits/4e95e12559c9c5364269ff366a59768573baacb4[WEB]
- https://github.com/nasa/openmct[PACKAGE]
- https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f[WEB]