CVE-2023-0745: Yugabyte Yugabytedb Managed

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0

Affected products

  • Yugabyte Yugabytedb Managed: from 2.0, up to and including 2.13

Published 2023-02-09. Last modified 2026-06-17.