Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Remediation
References
https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f
Related Vulnerabilities
CVE-2020-24616 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2010-0684 Vulnerability in maven package org.apache.activemq:activemq-web
CVE-2019-15955 Vulnerability in npm package total.js
CVE-2020-10719 Vulnerability in maven package io.undertow:undertow-core
CVE-2020-2243 Vulnerability in maven package org.jenkins-ci.plugins:vmanager-plugin