CVE-2023-45278

CRITICAL9.1EPSS 2.0%

Yamcs API Directory Traversal vulnerability

Published: 10/19/2023Modified: 2/16/2024
Also known as:GHSA-43fw-536j-w37j

Description

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

References (4)