CVE-2023-45279: XSS
Published Oct 19, 2023
·Updated
Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by selecting Telemetry from the menu and navigating to the display.
Affected Software
2 affected componentsFixes available
maven/org.yamcs:yamcs<5.8.7
5.8.7
Spaceapplications Yamcs=5.8.6
Remediation
Event History
Oct 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
10:15 PM
Description
Oct 20, 2023
Advisory Published
12:30 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-45279.
2
What is the severity of CVE-2023-45279?
The severity of CVE-2023-45279 is not provided.
3
How does CVE-2023-45279 affect Yamcs?
CVE-2023-45279 allows XSS in Yamcs 5.8.6 through a bucket's uploaded display.
4
How can I fix CVE-2023-45279?
To fix CVE-2023-45279, update Yamcs to version 5.8.7 or higher.
5
What is CWE-79?
CWE-79 refers to Cross-Site Scripting (XSS), which is the type of vulnerability present in CVE-2023-45279.