Skip to content

Commit

Permalink
Assign IDs
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions committed Nov 13, 2024
1 parent 079ff00 commit b4565fe
Show file tree
Hide file tree
Showing 2 changed files with 20 additions and 20 deletions.
2 changes: 1 addition & 1 deletion vulns/.id-allocator
Original file line number Diff line number Diff line change
@@ -1 +1 @@
56b7b6d525c341791888259c83d493ead31062dc4cd21e7a601cbcdf0c2497b1
fbb8cec03ade273450b3e22ae21d7ed5e8ac301203aedeb78f98f45e23d3c650
Original file line number Diff line number Diff line change
@@ -1,38 +1,29 @@
id: PYSEC-0000-CVE-2024-47529
id: PYSEC-2024-121
modified: 2024-11-13T20:22:56.434107Z
published: 2024-10-02T20:15:00Z
aliases:
- CVE-2024-47529
- GHSA-4xqv-47rm-37mm
details: OpenC3 COSMOS provides the functionality needed to send commands to and receive
data from one or more embedded systems. OpenC3 COSMOS stores the password of a user
unencrypted in the LocalStorage of a web browser. This makes the user password susceptible
to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability
is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS
Enterprise Edition.
aliases:
- CVE-2024-47529
- GHSA-4xqv-47rm-37mm
modified: '2024-11-13T20:22:56.434107Z'
published: '2024-10-02T20:15:00Z'
references:
- type: ADVISORY
url: https://github.com/OpenC3/cosmos/security/advisories/GHSA-4xqv-47rm-37mm
- type: FIX
url: https://github.com/OpenC3/cosmos/commit/b5ab34fe7fa54c0c8171c4aa3caf4e03d6f63bd7
- type: EVIDENCE
url: https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS
- type: ADVISORY
url: https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS
affected:
- package:
name: openc3
ecosystem: PyPI
name: openc3
purl: pkg:pypi/openc3
ranges:
- type: GIT
repo: https://github.com/OpenC3/cosmos
events:
- introduced: '0'
- introduced: "0"
- fixed: b5ab34fe7fa54c0c8171c4aa3caf4e03d6f63bd7
repo: https://github.com/OpenC3/cosmos
- type: ECOSYSTEM
events:
- introduced: '0'
- introduced: "0"
- fixed: 5.19.0
versions:
- 0.1.0
Expand Down Expand Up @@ -60,3 +51,12 @@ affected:
severity:
- type: CVSS_V3
score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
references:
- type: ADVISORY
url: https://github.com/OpenC3/cosmos/security/advisories/GHSA-4xqv-47rm-37mm
- type: FIX
url: https://github.com/OpenC3/cosmos/commit/b5ab34fe7fa54c0c8171c4aa3caf4e03d6f63bd7
- type: EVIDENCE
url: https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS
- type: ADVISORY
url: https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS

0 comments on commit b4565fe

Please sign in to comment.