CVE-2024-46977

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openc3:cosmos:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*

History

31 Oct 2024, 14:15

Type Values Removed Values Added
References
  • () https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS -

08 Oct 2024, 14:02

Type Values Removed Values Added
References () https://github.com/OpenC3/cosmos/commit/a34e61aea5a465f0ab3e57d833ae7ff4cafd710b - () https://github.com/OpenC3/cosmos/commit/a34e61aea5a465f0ab3e57d833ae7ff4cafd710b - Patch
References () https://github.com/OpenC3/cosmos/security/advisories/GHSA-8jxr-mccc-mwg8 - () https://github.com/OpenC3/cosmos/security/advisories/GHSA-8jxr-mccc-mwg8 - Vendor Advisory
CPE cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*
cpe:2.3:a:openc3:cosmos:*:*:*:*:enterprise:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Openc3 cosmos
Openc3

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) OpenC3 COSMOS proporciona la funcionalidad necesaria para enviar comandos a uno o más sistemas integrados y recibir datos de ellos. Una vulnerabilidad de path traversal dentro del método open_local_file de LocalMode permite que un usuario autenticado con los permisos adecuados descargue cualquier archivo .txt a través de ScreensController#show en el servidor web en el que se ejecuta COSMOS (según los permisos de archivo). Esta vulnerabilidad se corrigió en la versión 5.19.0.

02 Oct 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 20:15

Updated : 2024-10-31 14:15


NVD link : CVE-2024-46977

Mitre link : CVE-2024-46977

CVE.ORG link : CVE-2024-46977


JSON object : View

Products Affected

openc3

  • cosmos
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')