PT-2023-29482 · Yamcs · Yamcs
Andy Olchawa
+1
·
Published
2023-10-19
·
Updated
2023-10-25
·
CVE-2023-45279
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Yamcs version 5.8.6
Description
The issue allows for Cross-Site Scripting (XSS) attacks. It comes with a Bucket as its primary storage mechanism, which allows for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by selecting Telemetry from the menu and navigating to the display.
Recommendations
For Yamcs version 5.8.6, as a temporary workaround, consider disabling the ability to upload displays referencing external files to the bucket until a patch is available. Restrict access to the bucket to minimize the risk of exploitation. Avoid using the bucket's file upload feature in the affected version until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yamcs