CVE-2023-45885

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-45885
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-45885.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-45885
Aliases
Published
2023-11-09T17:15:08Z
Modified
2025-07-29T10:59:53.975675Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.

References

Affected packages

Git / github.com/nasa/openmct

Affected ranges

Type
GIT
Repo
https://github.com/nasa/openmct
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.14.0

1.*

1.7.8-rc1

V-R4.*

V-R4.4-41620
V-R4.4-RC4
V-R4.4-RC5

Other

list
openmct-viper-build-2-rc2
sim3

open-v0.*

open-v0.7.2
open-v0.8.0
open-v0.8.1

v0.*

v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.11.4
v0.12.0
v0.13.1
v0.13.2
v0.14.0
v0.8.2
v0.9.0
v0.9.1
v0.9.2
v0.9.3

v1.*

v1.2-RC1
v1.2-RC3
v1.2-rc2
v1.3.1
v1.4.0-rc5
v1.4.1-rc1
v1.4.1-rc2

v3.*

v3.1.0

vista-4.*

vista-4.1-rc2
vista-4.1-rc3
vista-4.1-rc4
vista-4.1-rc5
vista-4.1-rc6
vista-4.1-rc7
vista-4.1-rc8
vista-4.1.0
vista-4.1.1-rc1
vista-4.2-rc1
vista-4.2.0
vista-4.2.0-rc2
vista-4.2.0-rc3
vista-4.2.0-rc4
vista-4.2.0-rc5
vista-4.2.0-rc6
vista-4.3.0-rc1
vista-4.7.0-rc1
vista-4.7.0-rc2
vista-4.7.0-rc3
vista-4.7.0-rc5

vista-r4.*

vista-r4.3.0-rc3
vista-r4.3.1-rc1
vista-r4.8.0-rc1
vista-r4.8.0-rc2