{"id":"PYSEC-2024-101","details":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0.","aliases":["CVE-2024-46977","GHSA-8jxr-mccc-mwg8"],"modified":"2024-10-08T17:57:06.644535Z","published":"2024-10-02T20:15:00Z","references":[{"type":"ADVISORY","url":"https://github.com/OpenC3/cosmos/security/advisories/GHSA-8jxr-mccc-mwg8"},{"type":"FIX","url":"https://github.com/OpenC3/cosmos/commit/a34e61aea5a465f0ab3e57d833ae7ff4cafd710b"}],"affected":[{"package":{"name":"openc3","ecosystem":"PyPI","purl":"pkg:pypi/openc3"},"ranges":[{"type":"GIT","repo":"https://github.com/OpenC3/cosmos","events":[{"introduced":"0"},{"fixed":"a34e61aea5a465f0ab3e57d833ae7ff4cafd710b"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.19.0"}]}],"versions":["0.1.0","5.10.0","5.10.1","5.11.0","5.11.1","5.11.2","5.11.3","5.12.0","5.13.0","5.14.0","5.14.1","5.14.2","5.15.0","5.15.1","5.15.2","5.16.0","5.16.1","5.16.2","5.17.0","5.17.1","5.18.0","5.9.2b0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/openc3/PYSEC-2024-101.yaml"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}