
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross Site Request Forgery (CSRF) vulnerability was discovered in NASA Open MCT (Open Mission Control Technologies) through version 3.1.0. The vulnerability specifically affects the flexibleLayout plugin, allowing attackers to view sensitive information (NVD, CVE).
The vulnerability exists in the flexibleLayout plugin of Open MCT due to the lack of CSRF protection. The issue is particularly concerning as the examined version lacks CSP (Content Security Policy) flags. The vulnerability has been assigned a CVSS v3.1 Base Score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N (NVD).
The vulnerability allows attackers to view sensitive information through the flexibleLayout plugin. When combined with other vulnerabilities like XSS and the lack of CSP, it creates opportunities for system exploitation including potential unauthorized access to backend databases (LinkedIn Post).
The recommended mitigations include implementing CSP based on the OWASP cheat sheet and implementing CSRF countermeasures. Additionally, it is recommended to consider using sanitization methods, such as those already used in the Notebook plugin (NotebookEntry.vue:246) (LinkedIn Post).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."