Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Remediation
References
https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f
Related Vulnerabilities
CVE-2020-26238 Vulnerability in maven package com.cronutils:cron-utils
CVE-2020-28481 Vulnerability in maven package org.webjars.bower:socket.io
CVE-2018-14042 Vulnerability in npm package bootstrap
CVE-2022-25857 Vulnerability in maven package org.yaml:snakeyaml
CVE-2023-30516 Vulnerability in maven package org.jenkins-ci.plugins:image-tag-parameter