Skip to content

AIT Core v3.1.2

Latest

Choose a tag to compare

@EmilyPascua EmilyPascua released this 15 Sep 17:49

What's Changed

Fixed Vulnerabilities

  1. Path Traversal in Telemetry CSV Export (GHSA-93gm-4cqq-j774)
    - Malicious packet names can no longer write files outside intended directories
  2. Memory Exhaustion via REST API (GHSA-fjr5-6w4j-47xf)
    - Blocked file_name_pattern parameter from REST API to prevent attacks
    - Can only be set via configuration file
  3. Network Exposure Prevention (GHSA-ccw5-g774-3683)
    - ZeroMQ broker now binds to localhost by default instead of all network interfaces
    - Use SSH port forwarding for remote access
  4. OpenMCT Plugin Hardening (GHSA-7h55-xp8q-247v)
    - Binds to localhost by default
    - Prevents cross-site WebSocket attacks with Origin validation
    - Fixed crashes from malformed requests
    - Added security logging for debug endpoint access

Documentation

  • Added security warnings for command sequences with embedded shell commands
  • Updated server architecture documentation with security best practices

Full Changelog: 3.1.1...3.1.2