CVE-2023-45278

CRITICAL

Yamcs 5.8.6 - Path Traversal via Storage API DELETE Request

Title source: llm
STIX 2.1

Description

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

Scores

CVSS v3 9.1
EPSS 0.0202
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-22
Status published
Products (2)
org.yamcs/yamcs 0 - 5.8.7Maven
spaceapplications/yamcs 5.8.6
Published Oct 19, 2023
Tracked Since Feb 18, 2026