First published: Fri Oct 06 2023(Updated: )
In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nasa openmct | =2.2.5 | |
nasa openmct | <3.1.0 | |
npm/openmct | <=3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45282 is a vulnerability that exists in NASA Open MCT before commit 545a177, allowing for prototype pollution through an import action.
The severity of CVE-2023-45282 is high with a CVSS score of 7.5.
Prototype pollution can occur in NASA Open MCT through an import action.
Versions up to and including 2.2.5 of NASA Open MCT are affected by CVE-2023-45282.
To fix CVE-2023-45282 in NASA Open MCT, update to a version later than commit 545a177.