Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Remediation
References
https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f
Related Vulnerabilities
CVE-2022-36916 Vulnerability in maven package org.jenkins-ci.plugins:google-cloud-backup
CVE-2021-21165 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-28477 Vulnerability in npm package immer
CVE-2021-28170 Vulnerability in maven package org.glassfish:jakarta.el
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core