Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.9 RubyGems

OpenC3 stores passwords in clear text (`GHSL-2024-129`)

GHSA-4xqv-47rm-37mm · CVE-2024-47529 · PYSEC-2024-121

Published · Modified

Description

Summary

OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128).

Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition

Impact

This issue may lead to Information Disclosure.

Ready to move

Start Securing

Free, no credit card | First findings in minutes