CVE-2023-45282: High severity nasa openmct vulnerability
Published Oct 6, 2023
·Updated
In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
Other sources
In NASA Open MCT (aka openmct) before commit 545a177 is subject to a prototype pollution which can occur via an import action.
Affected Software
3 affected components
npm/openmct<=3.0.2
nasa openmct<3.1.0
nasa openmct=2.2.5
Remediation
Event History
Oct 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is CVE-2023-45282?
CVE-2023-45282 is a vulnerability that exists in NASA Open MCT before commit 545a177, allowing for prototype pollution through an import action.
2
What is the severity of CVE-2023-45282?
The severity of CVE-2023-45282 is high with a CVSS score of 7.5.
3
How can prototype pollution occur in NASA Open MCT?
Prototype pollution can occur in NASA Open MCT through an import action.
4
Which versions of NASA Open MCT are affected by CVE-2023-45282?
Versions up to and including 2.2.5 of NASA Open MCT are affected by CVE-2023-45282.
5
How can I fix CVE-2023-45282 in NASA Open MCT?
To fix CVE-2023-45282 in NASA Open MCT, update to a version later than commit 545a177.