Summary
A path traversal vulnerability inside of LocalMode
's open_local_file
method allows an authenticated user with adequate permissions to download any .txt
via the ScreensController#show
on the web server COSMOS is running on (depending on the file permissions).
Note: This CVE affects all OpenC3 COSMOS Editions
Impact
This issue may lead to Information Disclosure.
Summary
A path traversal vulnerability inside of
LocalMode
'sopen_local_file
method allows an authenticated user with adequate permissions to download any.txt
via theScreensController#show
on the web server COSMOS is running on (depending on the file permissions).Note: This CVE affects all OpenC3 COSMOS Editions
Impact
This issue may lead to Information Disclosure.