CVE-2024-43795

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*

History

31 Oct 2024, 14:15

Type Values Removed Values Added
References
  • () https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS -

08 Oct 2024, 14:01

Type Values Removed Values Added
CPE cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Openc3 cosmos
Openc3
References () https://github.com/OpenC3/cosmos/commit/762d7e0e93bdc2f340b1e42acccedc78994a576e - () https://github.com/OpenC3/cosmos/commit/762d7e0e93bdc2f340b1e42acccedc78994a576e - Patch
References () https://github.com/OpenC3/cosmos/security/advisories/GHSA-vfj8-5pj7-2f9g - () https://github.com/OpenC3/cosmos/security/advisories/GHSA-vfj8-5pj7-2f9g - Vendor Advisory

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) OpenC3 COSMOS proporciona la funcionalidad necesaria para enviar comandos a uno o más sistemas integrados y recibir datos de ellos. La funcionalidad de inicio de sesión contiene una vulnerabilidad de tipo cross-site scripting (XSS) reflejado. Esta vulnerabilidad se ha corregido en la versión 5.19.0. Nota: esta vulnerabilidad de vulnerabilidad de ejecución de comandos solo afecta a Open Source Edition, no a OpenC3 COSMOS Enterprise Edition.

02 Oct 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 20:15

Updated : 2024-10-31 14:15


NVD link : CVE-2024-43795

Mitre link : CVE-2024-43795

CVE.ORG link : CVE-2024-43795


JSON object : View

Products Affected

openc3

  • cosmos
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')