CVE-2024-43795

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*

History

31 Oct 2024, 14:15

Type Values Removed Values Added
References
  • () https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS -

08 Oct 2024, 14:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Openc3 cosmos
Openc3
References () https://github.com/OpenC3/cosmos/security/advisories/GHSA-vfj8-5pj7-2f9g - () https://github.com/OpenC3/cosmos/security/advisories/GHSA-vfj8-5pj7-2f9g - Vendor Advisory
References () https://github.com/OpenC3/cosmos/commit/762d7e0e93bdc2f340b1e42acccedc78994a576e - () https://github.com/OpenC3/cosmos/commit/762d7e0e93bdc2f340b1e42acccedc78994a576e - Patch
CPE cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:*

02 Oct 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 20:15

Updated : 2024-10-31 14:15


NVD link : CVE-2024-43795

Mitre link : CVE-2024-43795


JSON object : View

Products Affected

openc3

  • cosmos
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')