CVE-2022-23627

Summary

CVECVE-2022-23627
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-02-08 23:15:00 UTC
Updated2022-02-16 17:23:00 UTC
DescriptionArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like command sent to bot `A` targeting bot `B` has incorrectly verified user's access against bot `A` - instead of bot `B`, to which the command was originally designated. This in result allowed access to resources beyond those configured, being a security threat affecting confidentiality of other bot instances. A successful attack exploiting this bug requires a significant access granted explicitly by original owner of the ASF process prior to that, as attacker has to control at least a single bot in the process to make use of this inadequate access verification loophole. The issue is patched in ASF V5.2.2.5, V5.2.3.2 and future versions. Users are advised to update as soon as possible.

Risk And Classification

Problem Types: CWE-863

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Archisteamfarm Project Archisteamfarm All All All All

References

ReferenceSourceLinkTags
Closes #2500 by JustArchi · Pull Request #2501 · JustArchiNET/ArchiSteamFarm · GitHub MISC github.com
Fix permissions when proxifying commands (#2509) · JustArchiNET/ArchiSteamFarm@f807bdb · GitHub MISC github.com
Release ArchiSteamFarm V5.2.2.5 · JustArchiNET/ArchiSteamFarm · GitHub MISC github.com
Fix permissions when proxifying commands · JustArchiNET/ArchiSteamFarm@7a29d92 · GitHub MISC github.com
Inadequate access verification when using proxy commands (< 5.2.2.5, < 5.2.3.2) · Advisory · JustArchiNET/ArchiSteamFarm · GitHub CONFIRM github.com
Release 5.2.3.2 · JustArchiNET/ArchiSteamFarm · GitHub MISC github.com
Fix permissions when proxifying commands by JustArchi · Pull Request #2509 · JustArchiNET/ArchiSteamFarm · GitHub MISC github.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report