Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 RubyGems

OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)

GHSA-8jxr-mccc-mwg8 · CVE-2024-46977 · PYSEC-2024-101

Published · Modified

Description

Summary

A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions).

Note: This CVE affects all OpenC3 COSMOS Editions

Impact

This issue may lead to Information Disclosure.

Ready to move

Start Securing

Free, no credit card | First findings in minutes