Description
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.
Remediation
References
https://github.com/yamcs/yamcs/compare/yamcs-5.8.6...yamcs-5.8.7
https://www.linkedin.com/pulse/yamcs-vulnerability-assessment-visionspace-technologies
Related Vulnerabilities
CVE-2015-8855 Vulnerability in npm package semver
CVE-2021-23771 Vulnerability in npm package notevil
CVE-2023-36471 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml
CVE-2021-43138 Vulnerability in maven package org.webjars.npm:async
CVE-2022-3952 Vulnerability in maven package com.manydesigns:portofino-microservice-launcher