Junglewise Threat Intelligence

CVE-2023-45884: NASA Open MCT cross-site request forgery in flexibleLayout plugin

CVE-2023-45884 · Severity: low · CVSS 3.1 · Published 2023-11-09

Technologies: Nasa Open MCT, openmct (npm). Vendors: Nasa, npm.

Executive brief

NASA Open MCT is a web-based mission control framework used to monitor and manage space operations. A cross-site request forgery vulnerability in the flexibleLayout plugin could allow attackers to craft malicious requests that trick authenticated users into performing unintended actions, such as viewing or exfiltrating sensitive mission data. The vulnerability is especially dangerous when combined with existing XSS flaws and the absence of Content Security Policy protections.

Technical details

This CSRF vulnerability (CWE-352) exists in NASA Open MCT versions up to 3.1.0 within the flexibleLayout plugin component. The root cause is the absence of CSRF protections (such as anti-CSRF tokens or SameSite cookie attributes) in the application. The attack is primarily network-based and requires user interaction—an authenticated user must be tricked into visiting a malicious webpage or performing an action while logged into Open MCT. When chained with the existing stored XSS flaw in the flexibleLayout component (triggered during drag-and-drop operations in edit mode), an attacker can inject malicious JavaScript that performs arbitrary API calls to the backend database on behalf of the victim, exfiltrating mission-critical data. The vulnerability was fixed in version 3.1.1, which added the eslint-plugin-no-unsanitized plugin and properly sanitized user-controlled input in the affected components.

Affected products

  • NASA Open MCT through 3.1.0

Timeline

  • 2023-11-09: disclosed: CVE-2023-45884 published
  • 2023-10-23: patched: Fix merged in release/3.1.1

References

Related threats