Skip to content

Clear text storage of password/token (`GHSL-2024-129`)

Moderate
ryanmelt published GHSA-4xqv-47rm-37mm Oct 2, 2024

Package

bundler openc3 (RubyGems)

Affected versions

< 5.19.0

Patched versions

5.19.0

Description

Summary

OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128).

Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition

Impact

This issue may lead to Information Disclosure.

Severity

Moderate

CVE ID

CVE-2024-47529

Weaknesses

Credits