CVE-2024-43795: GHSL-2024-127_GHSL-2024-129: Remote Code Execution (RCE) via Cross-Site Scripting (XSS) in OpenC3 COSMOS - CVE-2024-43795, CVE-2024-46977, CVE-2024-47529
Summary The login functionality contains a reflected cross-site scripting (XSS) vulnerability.
Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition
Impact This issue may lead up to Remote Code Execution (RCE).
Other sources
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition.
— MITRE
Several vulnerabilities were found in OpenC3 COSMOS, a web application that is used to control satellites and test equipment. They can lead up to Remote Code Execution (RCE) via cross-site scripting (XSS).
— GitHub Security Lab
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43795?
CVE-2024-43795 is considered a high severity vulnerability due to its potential to lead to Remote Code Execution (RCE).
How do I fix CVE-2024-43795?
To fix CVE-2024-43795, update OpenC3 COSMOS to version 5.19.0 or later.
What type of vulnerability is CVE-2024-43795?
CVE-2024-43795 is a reflected cross-site scripting (XSS) vulnerability affecting the login functionality.
Which versions of OpenC3 COSMOS are affected by CVE-2024-43795?
CVE-2024-43795 affects all versions of OpenC3 COSMOS prior to 5.19.0 in the Open Source Edition.
Does CVE-2024-43795 affect the OpenC3 COSMOS Enterprise Edition?
No, CVE-2024-43795 only affects the Open Source Edition of OpenC3 COSMOS.