Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFacto…
Critical CVSS 9.1
Summary
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm's text via the mission database REST API and inject Java …
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011 Patch
- https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992 Patch
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7 Release Notes
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0 Release Notes
- https://github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6 Exploit
- https://github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6 Exploit
Timeline
- nvd_ingest NVD