CVE-2023-45278: Path Traversal
Published Oct 19, 2023
·Updated
Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.
Affected Software
2 affected componentsFixes available
maven/org.yamcs:yamcs<5.8.7
5.8.7
Spaceapplications Yamcs=5.8.6
Remediation
Event History
Oct 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
05:15 PM
Description
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Yamcs vulnerability?
The vulnerability ID for this Yamcs vulnerability is CVE-2023-45278.
2
What is the description of the Yamcs vulnerability?
The Yamcs vulnerability is a directory traversal vulnerability that allows attackers to delete arbitrary files via a crafted HTTP DELETE request.
3
What software versions are affected by the Yamcs vulnerability?
Yamcs versions up to and including 5.8.6 are affected by the vulnerability.
4
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by sending crafted HTTP DELETE requests to the API's storage functionality in Yamcs 5.8.6, allowing them to delete arbitrary files.
5
How can I remediate this Yamcs vulnerability?
To remediate this Yamcs vulnerability, update to version 5.8.7 or later of the yamcs package.