CVE-2022-23054

Source
https://cve.org/CVERecord?id=CVE-2022-23054
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23054.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23054
Published
2022-02-20T19:00:17Z
Modified
2026-07-15T01:49:04.714670415Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Openmct XSS via the “Summary Widget”
Details

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

Database specific
{
    "cna_assigner": "Mend",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23054.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/nasa/openmct

Affected ranges

Type
GIT
Repo
https://github.com/nasa/openmct
Events
Database specific
{
    "cpe": "cpe:2.3:a:nasa:openmct:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "last_affected": "1.7.7"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.7.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23054.json"