The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary
files through the backup upload endpoint by using path traversal characters.













This vulnerability is associated with program files PlatformReplicationManager.Java.

This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0

Advisories
Source ID Title
EUVD EUVD EUVD-2023-12763 The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0
Fixes

Solution

Fixed in version 2.14 onwards .


Workaround

No workaround given by the vendor.

References
Link Providers
https://www.yugabyte.com/ cve-icon cve-icon
History

Mon, 24 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Yugabyte

Published:

Updated: 2025-03-24T18:33:37.528Z

Reserved: 2023-02-08T12:08:53.977Z

Link: CVE-2023-0745

cve-icon Vulnrichment

Updated: 2024-08-02T05:24:34.100Z

cve-icon NVD

Status : Modified

Published: 2023-02-09T17:15:16.553

Modified: 2024-11-21T07:37:44.537

Link: CVE-2023-0745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.