The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0
References
Link Providers
https://www.yugabyte.com/ cve-icon cve-icon
History

Mon, 24 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Yugabyte

Published:

Updated: 2025-03-24T18:33:37.528Z

Reserved: 2023-02-08T12:08:53.977Z

Link: CVE-2023-0745

cve-icon Vulnrichment

Updated: 2024-08-02T05:24:34.100Z

cve-icon NVD

Status : Modified

Published: 2023-02-09T17:15:16.553

Modified: 2024-11-21T07:37:44.537

Link: CVE-2023-0745

cve-icon Redhat

No data.