MEDIUM5.4
GHSA-v8fc-qxvj-f3mg
NASA Open MCT Cross Site Scripting vulnerability
Details
Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the `flexibleLayout` plugin.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/openmct
Introduced in:
0No fixed version published yet for openmct (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-45885[ADVISORY]
- https://github.com/nasa/openmct/pull/7148[WEB]
- https://github.com/nasa/openmct/pull/7148/commits/4e95e12559c9c5364269ff366a59768573baacb4[WEB]
- https://github.com/nasa/openmct[PACKAGE]
- https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f[WEB]