Headline
GHSA-w4m2-qmh3-2g8f: Yamcs Path Traversal vulnerability
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.
Yamcs Path Traversal vulnerability
Moderate severity GitHub Reviewed Published Oct 19, 2023 to the GitHub Advisory Database • Updated Oct 19, 2023
Related news
CVE-2023-45281: Yamcs v5.8.6 Vulnerability Assessment
An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.