GHSL-2024-127: _GHSL-2024-129: Remote Code Execution (RCE) via Cross-Site Scripting (XSS) in OpenC3 COSMOS - CVE-2024-43795, CVE-2024-46977, CVE-2024-47529
Published Oct 17, 2024
·Updated
Several vulnerabilities were found in OpenC3 COSMOS, a web application that is used to control satellites and test equipment. They can lead up to Remote Code Execution (RCE) via cross-site scripting (XSS).
Affected Software
1 affected component
OpenC3 OpenC3 COSMOS
Event History
Oct 17, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2024-129?
GHSL-2024-129 has a severity rating of 77, indicating a high risk level.
2
What type of vulnerability is GHSL-2024-129?
GHSL-2024-129 involves Remote Code Execution (RCE) via Cross-Site Scripting (XSS) vulnerabilities.
3
Which software is affected by GHSL-2024-129?
GHSL-2024-129 affects the OpenC3 COSMOS web application.
4
How do I fix GHSL-2024-129?
To mitigate GHSL-2024-129, update your OpenC3 COSMOS installation to the latest version that includes patches for the identified vulnerabilities.
5
What are the CVE identifiers associated with GHSL-2024-129?
GHSL-2024-129 is associated with CVE-2024-43795, CVE-2024-46977, and CVE-2024-47529.