Vulnerabilities/

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Severity:
Medium

Description

Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.

Recommendation

Update the openmct package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
openmct
Anything's wrong? Let us know Last updated on November 22, 2023

This issue is available in SmartScanner Professional

See Pricing