A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers.
The product uses an environment variable to store unencrypted sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cosmos | Openc3 | 6.0.0 (including) | 6.0.0 (including) |