CVE-2023-45884

MEDIUM6.5EPSS 0.07%

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Published: 11/9/2023Modified: 11/15/2023
Also known as:GHSA-4g88-4hgm-m99x

Description

Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

References (5)