Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess chec…
Medium CVSS 4.3
Summary
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/yamcs/yamcs/commit/0e12b518f103f24681299318a30a460fe4327b88 Patch
- https://github.com/yamcs/yamcs/commit/e90099fba98e96214217c195b6a5b87b5f46e51c Patch
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7 Release Notes
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0 Release Notes
- https://github.com/yamcs/yamcs/security/advisories/GHSA-p2rj-mrmc-9w29 Exploit
Timeline
- nvd_ingest NVD