Medium severity6.5NVD Advisory· Published Nov 9, 2023· Updated Jun 17, 2026
CVE-2023-45884
CVE-2023-45884
Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openmctnpm | < 3.1.1 | 3.1.1 |
Affected products
3- NASA/Open MCTdescription
Patches
Vulnerability mechanics
References
5- www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4fnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-4g88-4hgm-m99xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-45884ghsaADVISORY
- github.com/nasa/openmct/pull/7148ghsaWEB
- github.com/nasa/openmct/pull/7148/commits/4e95e12559c9c5364269ff366a59768573baacb4ghsaWEB
News mentions
0No linked articles in our index yet.