Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Recommendation
Update the openmct package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.1.0
- Patched version(s): 3.1.1
References
Related Issues
- NASA Open MCT Cross Site Scripting vulnerability - CVE-2023-45885
- @builder.io/qwik-city Cross-Site Request Forgery vulnerability - CVE-2023-2307
- Axios Cross-Site Request Forgery Vulnerability - CVE-2023-45857
- Cross-Site Request Forgery (CSRF) in Auth0 - CVE-2018-6874
You might also like:
- Tags:
- npm
- openmct
Anything's wrong? Let us know Last updated on November 22, 2023


