Directory Traversal Vulnerability in Yamcs 5.8.6 Storage Functionality

Directory Traversal Vulnerability in Yamcs 5.8.6 Storage Functionality

CVE-2023-45277 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

Learn more about our Api Penetration Testing.