First published: Sun Feb 20 2022(Updated: )
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
nasa openmct | >=1.3.0<=1.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23054 is a vulnerability in Openmct versions 1.3.0 to 1.7.7 that allows for stored cross-site scripting (XSS) attacks.
CVE-2022-23054 affects Openmct versions 1.3.0 to 1.7.7 by allowing the injection of malicious JavaScript through the 'URL' field in the 'Summary Widget' element.
CVE-2022-23054 has a severity rating of medium with a CVSS score of 6.1.
To fix CVE-2022-23054, update Openmct to version 1.7.8 or later.
For more information about CVE-2022-23054, you can refer to the GitHub commit at https://github.com/nasa/openmct/commit/abc93d0ec4b104dac1ea5f8a615d06e3ab78934a.