Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0128 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. |
Github GHSA |
GHSA-4xqv-47rm-37mm | OpenC3 stores passwords in clear text (`GHSL-2024-129`) |
Wed, 13 Nov 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openc3
Openc3 cosmos |
|
| CPEs | cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:* | |
| Vendors & Products |
Openc3
Openc3 cosmos |
|
| Metrics |
cvssV3_1
|
Thu, 31 Oct 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 02 Oct 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. | |
| Title | OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`) | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-31T13:52:49.907Z
Reserved: 2024-09-25T21:46:10.929Z
Link: CVE-2024-47529
Updated: 2024-10-02T19:52:56.533Z
Status : Analyzed
Published: 2024-10-02T20:15:11.740
Modified: 2024-11-13T17:15:46.543
Link: CVE-2024-47529
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA