CVE-2024-46977: GHSL-2024-127_GHSL-2024-129: Remote Code Execution (RCE) via Cross-Site Scripting (XSS) in OpenC3 COSMOS - CVE-2024-43795, CVE-2024-46977, CVE-2024-47529
Summary A path traversal vulnerability inside of LocalMode's openlocalfile method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions).
Note: This CVE affects all OpenC3 COSMOS Editions
Impact This issue may lead to Information Disclosure.
Other sources
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's openlocalfile method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0.
— MITRE
Several vulnerabilities were found in OpenC3 COSMOS, a web application that is used to control satellites and test equipment. They can lead up to Remote Code Execution (RCE) via cross-site scripting (XSS).
— GitHub Security Lab
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46977?
CVE-2024-46977 is classified as a medium severity vulnerability due to its potential exploitation by authenticated users with sufficient permissions.
How do I fix CVE-2024-46977?
To fix CVE-2024-46977, update OpenC3 COSMOS to version 5.19.0 or later.
What type of vulnerability is CVE-2024-46977?
CVE-2024-46977 is a path traversal vulnerability affecting the open_local_file method in OpenC3 COSMOS.
Who is affected by CVE-2024-46977?
Authenticated users with adequate permissions on OpenC3 COSMOS versions prior to 5.19.0 are affected by CVE-2024-46977.
What can attackers do with CVE-2024-46977?
Attackers can use CVE-2024-46977 to download arbitrary .txt files from the server, depending on file permissions.