Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-10-19T00:00:00

Updated: 2023-10-19T16:28:18.356831

Reserved: 2023-10-06T00:00:00


Link: CVE-2023-45277

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-19T17:15:10.150

Modified: 2023-10-25T14:48:18.060


Link: CVE-2023-45277

JSON object: View

cve-icon Redhat Information

No data.

CWE