CVE-2020-16136
Summary
| CVE | CVE-2020-16136 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-31 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory traversal ../ sequences in /Administration/Logs/ requests. The attacker is unable to enumerate files, however. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tgstation13 | Tgstation-server | 4.4.0 | All | All | All |
| Application | Tgstation13 | Tgstation-server | 4.4.1 | All | All | All |
| Application | Tgstation13 | Tgstation-server | 4.4.0 | All | All | All |
| Application | Tgstation13 | Tgstation-server | 4.4.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - tgstation/tgstation-server: A production scale tool for BYOND server management | MISC | github.com | Third Party Advisory |
| Log Downloading Could Traverse Entire Filesystem · Advisory · tgstation/tgstation-server · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.