PT-2023-29480 · Yamcs · Yamcs

Andy Olchawa

+1

·

Published

2023-10-19

·

Updated

2023-10-25

·

CVE-2023-45277

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yamcs version 5.8.6
Description The issue is related to directory traversal in the storage functionality of the API, allowing an attacker to escape the base directory of the buckets, navigate system directories, and read arbitrary files.
Recommendations For Yamcs version 5.8.6, as a temporary workaround, consider restricting access to the storage functionality of the API until a patch is available. Avoid using the API to navigate system directories or read arbitrary files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-45277
GHSA-W4M2-QMH3-2G8F

Affected Products

Yamcs