QID 995678
Date Published: 2023-10-25
QID 995678: Java (Maven) Security Update for org.yamcs:yamcs (GHSA-4cqv-q33x-wfxw)
Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by selecting Telemetry from the menu and navigating to the display.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4cqv-q33x-wfxw for updates and patch information.
Vendor References
- GHSA-4cqv-q33x-wfxw -
github.com/advisories/GHSA-4cqv-q33x-wfxw
CVEs related to QID 995678
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4cqv-q33x-wfxw | org.yamcs:yamcs |
|