Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Recommendation
Update the openmct
package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.1.0
- Patched version(s): 3.1.1
References
Related Issues
- The AuthKit Remix Library renders sensitive auth data in HTML - CVE-2025-55009
- Strapi allows Server-Side Request Forgery in Webhook function - CVE-2024-52588
- Redoc Prototype Pollution via `Module.mergeObjects` Component - CVE-2024-57083
- Angular Expressions - Remote Code Execution when using locals - CVE-2024-54152
- Tags:
- npm
- openmct
Anything's wrong? Let us know Last updated on November 22, 2023