Description
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- spaceapplications / yamcs5.12.7
- yamcs / yamcs< 5.12.7 – < 5.12.7
Exploits & proofs of concept
- exploit-dbYAMCS yamcs-core 5.12.7 - No Rate Limitingby Daniel Miranda
References
- VENDOR_ADVISORYhttps://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4
- PATCHhttps://github.com/yamcs/yamcs/commit/309218c651680f79df11a8d0f8628f7033f98a83
- PATCHhttps://github.com/yamcs/yamcs/commit/64392df531fbcbc65f19ee5724c4c23d289f49fc
- PATCHhttps://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7
- PATCHhttps://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0
Updated 13m ago · 8 sources