CVE-2024-47529

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*

History

13 Nov 2024, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Openc3 cosmos
Openc3
References () https://github.com/OpenC3/cosmos/commit/b5ab34fe7fa54c0c8171c4aa3caf4e03d6f63bd7 - () https://github.com/OpenC3/cosmos/commit/b5ab34fe7fa54c0c8171c4aa3caf4e03d6f63bd7 - Patch
References () https://github.com/OpenC3/cosmos/security/advisories/GHSA-4xqv-47rm-37mm - () https://github.com/OpenC3/cosmos/security/advisories/GHSA-4xqv-47rm-37mm - Vendor Advisory
References () https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS - () https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS - Exploit, Third Party Advisory
CPE cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*

31 Oct 2024, 14:15

Type Values Removed Values Added
References
  • () https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS -

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) OpenC3 COSMOS proporciona la funcionalidad necesaria para enviar comandos a uno o más sistemas integrados y recibir datos de ellos. OpenC3 COSMOS almacena la contraseña de un usuario sin cifrar en el almacenamiento local de un navegador web. Esto hace que la contraseña del usuario sea susceptible a la exfiltración mediante Cross-Site Scripting (consulte GHSL-2024-128). Esta vulnerabilidad se ha corregido en la versión 5.19.0. Esto solo afecta a la edición Open Source, no a la OpenC3 COSMOS Enterprise Edition.

02 Oct 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 20:15

Updated : 2024-11-13 17:15


NVD link : CVE-2024-47529

Mitre link : CVE-2024-47529

CVE.ORG link : CVE-2024-47529


JSON object : View

Products Affected

openc3

  • cosmos
CWE
CWE-312

Cleartext Storage of Sensitive Information