CVE-2022-23054: Openmct XSS via the “Summary Widget”
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-23054?
CVE-2022-23054 is a vulnerability in Openmct versions 1.3.0 to 1.7.7 that allows for stored cross-site scripting (XSS) attacks.
How does CVE-2022-23054 affect Openmct?
CVE-2022-23054 affects Openmct versions 1.3.0 to 1.7.7 by allowing the injection of malicious JavaScript through the 'URL' field in the 'Summary Widget' element.
What is the severity of CVE-2022-23054?
CVE-2022-23054 has a severity rating of medium with a CVSS score of 6.1.
How can I fix CVE-2022-23054?
To fix CVE-2022-23054, update Openmct to version 1.7.8 or later.
Where can I find more information about CVE-2022-23054?
For more information about CVE-2022-23054, you can refer to the GitHub commit at https://github.com/nasa/openmct/commit/abc93d0ec4b104dac1ea5f8a615d06e3ab78934a.