QID 995633
Date Published: 2023-10-25
QID 995633: Java (Maven) Security Update for org.yamcs:yamcs (GHSA-w4m2-qmh3-2g8f)
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-w4m2-qmh3-2g8f for updates and patch information.
Vendor References
- GHSA-w4m2-qmh3-2g8f -
github.com/advisories/GHSA-w4m2-qmh3-2g8f
CVEs related to QID 995633
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w4m2-qmh3-2g8f | org.yamcs:yamcs |
|