CVE-2022-23053

Source
https://cve.org/CVERecord?id=CVE-2022-23053
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23053.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23053
Published
2022-02-20T19:00:15Z
Modified
2026-07-15T01:49:01.118382357Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Openmct XSS via the “Condition Widget”
Details

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

Database specific
{
    "cna_assigner": "Mend",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23053.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/nasa/openmct

Affected ranges

Type
GIT
Repo
https://github.com/nasa/openmct
Events
Database specific
{
    "cpe": "cpe:2.3:a:nasa:openmct:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "last_affected": "1.7.7"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.7.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23053.json"