Junglewise Threat Intelligence

CVE-2023-45885: NASA Open MCT cross-site scripting in flexibleLayout plugin

CVE-2023-45885 · Severity: low · CVSS 3.1 · Published 2023-11-09

Technologies: Nasa Open MCT, openmct (npm). Vendors: Nasa, npm.

Executive brief

NASA Open MCT is an open-source web-based mission control platform used to display and manage spacecraft telemetry and operations data. A cross-site scripting (XSS) vulnerability in the flexibleLayout plugin allows authenticated users to inject and execute arbitrary JavaScript code, potentially enabling account compromise, data theft, or malicious actions performed on behalf of legitimate users viewing the affected interface.

Technical details

A cross-site scripting (CWE-79) vulnerability exists in the flexibleLayout plugin's new component feature in NASA Open MCT versions up to 3.1.0. The vulnerability stems from insufficient input sanitization when handling component content, allowing an authenticated attacker to inject malicious JavaScript that executes in the context of other users' browsers. Attack preconditions include authentication (PR:L) and user interaction (UI:R) to view the crafted payload. The vulnerability has a network attack vector (AV:N) with low complexity (AC:L) and impacts confidentiality and integrity across security boundaries (S:C). A patch was implemented in the development branch via PR #7148, which adds eslint-plugin-no-unsanitized to enforce proper output encoding throughout the codebase.

Affected products

  • NASA Open MCT through 3.1.0

Timeline

  • 2023-11-09: disclosed
  • 2023-10-23: patched: Fix merged in release/3.1.1 branch via PR #7148

References

Related threats