Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-45278: Comparing yamcs-5.8.6...yamcs-5.8.7 · yamcs/yamcs

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

CVE
#vulnerability

Commits on Sep 18, 2023

  1. Browse the repository at this point in the history

Commits on Sep 23, 2023

  1. Browse the repository at this point in the history

  2. Browse the repository at this point in the history

  3. Browse the repository at this point in the history

Commits on Sep 25, 2023

  1. Browse the repository at this point in the history

Commits on Sep 29, 2023

  1. Browse the repository at this point in the history

  2. Browse the repository at this point in the history

  3. Browse the repository at this point in the history

Related news

GHSA-43fw-536j-w37j: Yamcs API Directory Traversal vulnerability

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

CVE-2023-45281: Yamcs v5.8.6 Vulnerability Assessment

An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907