CVE-2023-32687
Summary
| CVE | CVE-2023-32687 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-29 21:15:00 UTC |
| Updated | 2023-06-06 15:12:00 UTC |
| Description | tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bots permission can read chat bot connections strings without the associated permission. This issue is patched in version 5.12.1. As a workaround, remove the list chat bots permission from users that should not have the ability to view connection strings. Invalidate any credentials previously stored for safety. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tgstation13 | Tgstation-server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Insufficiently Protected ChatBot Credentials in tgstation-server · Advisory · tgstation/tgstation-server · GitHub | MISC | github.com | |
| Release tgstation-server-v5.12.1 · tgstation/tgstation-server · GitHub | MISC | github.com | |
| Fix exploit allowing for the reading of discord connection strings. by MrStonedOne · Pull Request #1487 · tgstation/tgstation-server · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.