CVE-2023-45280: XSS
Published Oct 19, 2023
·Updated
Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript.
Affected Software
2 affected componentsFixes available
maven/org.yamcs:yamcs<5.8.7
5.8.7
Spaceapplications Yamcs=5.8.6
Remediation
Event History
Oct 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
10:15 PM
Description
Oct 20, 2023
Advisory Published
12:30 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-45280.
2
What is the severity level of CVE-2023-45280?
The severity level of CVE-2023-45280 is not provided in the information provided.
3
How does CVE-2023-45280 affect Yamcs?
CVE-2023-45280 allows XSS in Yamcs 5.8.6, which allows the execution of arbitrary JavaScript.
4
How can I fix CVE-2023-45280 in Yamcs?
To fix CVE-2023-45280, upgrade Yamcs to version 5.8.7.
5
Where can I find more information about CVE-2023-45280?
You can find more information about CVE-2023-45280 on the GitHub repository, LinkedIn post, and NVD website provided in the references.