First published: Wed Oct 02 2024(Updated: )
### Summary The login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ### Impact This issue may lead up to Remote Code Execution (RCE). **NOTE:** The complete advisory with much more information is added as [comment](https://github.com/OpenC3/cosmos/security/advisories/GHSA-vfj8-5pj7-2f9g#advisory-comment-104904).
Affected Software | Affected Version | How to fix |
---|---|---|
pip/openc3 | <5.19.0 | 5.19.0 |
npm/@openc3/tool-common | <5.19.0 | 5.19.0 |
rubygems/openc3 | <5.19.0 | 5.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.