5.13.0
10 years ago
28 days ago
Known vulnerabilities in the org.yamcs:yamcs-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the Note: This is only exploitable if the deployment is running in the default configuration without a How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')? Upgrade | [,5.12.7) |
Affected versions of this package are vulnerable to Arbitrary Code Injection via the dynamic evaluation of user-supplied algorithm code in the script evaluation engine. An attacker can execute arbitrary operating system commands by injecting malicious Jython code through the REST API when authenticated with the required privileges. Note: This is only exploitable if the attacker has the How to fix Arbitrary Code Injection? Upgrade | [,5.12.7) |
Affected versions of this package are vulnerable to Brute Force through the How to fix Brute Force? Upgrade | [,5.12.7) |
Affected versions of this package are vulnerable to Arbitrary Code Injection in the Note: This is only exploitable if the attacker possesses valid credentials with the required privilege and can access a running instance with an active processor. How to fix Arbitrary Code Injection? Upgrade | [,5.12.7) |
Affected versions of this package are vulnerable to Missing Authorization in the IAM API endpoints, including How to fix Missing Authorization? Upgrade | [,5.12.7) |
Affected versions of this package are vulnerable to LDAP Injection via the Note: This is only exploitable if the deployment uses How to fix LDAP Injection? Upgrade | [,5.12.7) |
Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames allowing an attacker to create a website that would encourage the user to perform specific actions. This type of vulnerability can have an exceptionally high impact on control systems, such as this package. How to fix Improper Restriction of Rendered UI Layers or Frames? There is no fixed version for | [0,) |