PT-2023-24767 · Tgstation · Tgstation
Craftxbox
·
Publicado
2023-06-08
·
Atualizado
2023-06-15
·
CVE-2023-34243
CVSS v3.1
5.8
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TGstation versions prior to 5.12.5
Description
TGstation is a toolset to manage production BYOND servers. In affected versions, if a Windows user was registered in tgstation-server (TGS), an attacker could discover their username by brute-forcing the "login endpoint" with an invalid password. When a valid Windows logon was found, a distinct response would be generated.
Recommendations
For versions prior to 5.12.5, upgrade to version 5.12.5 to resolve the issue.
As a temporary workaround for users unable to upgrade, consider rate-limiting API calls with software that sits in front of TGS in the HTTP pipeline, such as fail2ban.
Exploit
Correção
Improper Restriction of Excessive Authentication Attempts
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tgstation