CVE-2024-46977

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
02/10/2024
Last modified:
31/10/2024

Description

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openc3:cosmos:*:*:*:*:enterprise:*:*:* 5.19.0 (excluding)
cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:* 5.19.0 (excluding)