Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0127 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. |
Github GHSA |
GHSA-8jxr-mccc-mwg8 | OpenC3 Path Traversal via screen controller (`GHSL-2024-127`) |
Thu, 31 Oct 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 08 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openc3
Openc3 cosmos |
|
| CPEs | cpe:2.3:a:openc3:cosmos:*:*:*:*:enterprise:*:*:* cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:* |
|
| Vendors & Products |
Openc3
Openc3 cosmos |
|
| Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. | |
| Title | OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-31T13:54:04.947Z
Reserved: 2024-09-16T16:10:09.017Z
Link: CVE-2024-46977
Updated: 2024-10-02T19:53:46.128Z
Status : Modified
Published: 2024-10-02T20:15:11.400
Modified: 2024-10-31T14:15:05.870
Link: CVE-2024-46977
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA