The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary
files through the backup upload endpoint by using path traversal characters.
This vulnerability is associated with program files PlatformReplicationManager.Java.
This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12763 | The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0 |
Fixes
Solution
Fixed in version 2.14 onwards .
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.yugabyte.com/ |
|
History
Mon, 24 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Yugabyte
Published:
Updated: 2025-03-24T18:33:37.528Z
Reserved: 2023-02-08T12:08:53.977Z
Link: CVE-2023-0745
Updated: 2024-08-02T05:24:34.100Z
Status : Modified
Published: 2023-02-09T17:15:16.553
Modified: 2024-11-21T07:37:44.537
Link: CVE-2023-0745
No data.
OpenCVE Enrichment
No data.
EUVD