CVE-2023-45277
Yamcs Path Traversal vulnerability
7.5
HIGH
CVSS 3.1
EPSS 1.3%
Description
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.
How to fix CVE-2023-45277
To remediate CVE-2023-45277, upgrade the affected package to a fixed version below.
- Maven/org.yamcs:yamcs—upgrade to 5.8.7 or later
Is CVE-2023-45277 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.8.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |