CVE-2023-0745: Arbitrary File Write in High Availability Backup Upload
Relative Path Traversal vulnerability in YugaByte, Inc. Yugabyte Managed (PlatformReplicationManager.Java modules) allows Path Traversal. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects Yugabyte Managed: from 2.0 through 2.13.
Other sources
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters.
This vulnerability is associated with program files PlatformReplicationManager.Java.
This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this YugaByte vulnerability?
The vulnerability ID for this YugaByte vulnerability is CVE-2023-0745.
What is the severity of CVE-2023-0745?
CVE-2023-0745 has a severity rating of 9.8 (Critical).
What is the affected software for CVE-2023-0745?
The affected software for CVE-2023-0745 is Yugabyte Managed version 2.0 through 2.13.
What is the CWE associated with CVE-2023-0745?
The CWE associated with CVE-2023-0745 are CWE-22 and CWE-23.
Is there a fix available for CVE-2023-0745?
Yes, fixing CVE-2023-0745 requires updating the affected Yugabyte Managed software to a version that addresses the vulnerability.