CVE-2023-45277
HIGH7.5EPSS 1.3%Yamcs Path Traversal vulnerability
Published: 10/19/2023Modified: 2/16/2024
Description
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.
Affected packages (1)
- Maven/org.yamcs:yamcsfrom 0, < 5.8.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |