Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Prototype Pollution in NASAs Open MCT CVE-2023-45282

published on 2024-11-22 20:37:06 UTC by /u/andy-codes
Content:

In the article, I discuss a prototype pollution vulnerability (CVE-2023-45282) found in NASA's Open MCT. This flaw in JavaScript allows attackers to alter object prototypes, potentially leading to serious outcomes like privilege escalation or remote code execution (RCE). I explain how the vulnerability occurs in the "Import from JSON" feature, which can crash the application or lead to more dangerous exploits. Fortunately, NASA responded quickly to fix the issue, but it highlights the importance of securing deep merge operations in JavaScript.

This security research was originally published at VisionSpace Blog (https://visionspace.com/prototype-pollution-in-nasas-open-mct-cve-2023-45282/).

submitted by /u/andy-codes
[link] [comments]
Article: Prototype Pollution in NASAs Open MCT CVE-2023-45282 - published about 12 hours ago.

https://www.reddit.com/r/netsec/comments/1gxhpmv/prototype_pollution_in_nasas_open_mct_cve202345282/   
Published: 2024 11 22 20:37:06
Received: 2024 11 22 20:40:02
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 0

Custom HTML Block

Click to Open Code Editor