PT-2023-24767 · Tgstation · Tgstation
Craftxbox
·
Published
2023-06-08
·
Updated
2023-06-15
·
CVE-2023-34243
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TGstation versions prior to 5.12.5
Description
TGstation is a toolset to manage production BYOND servers. In affected versions, if a Windows user was registered in tgstation-server (TGS), an attacker could discover their username by brute-forcing the "login endpoint" with an invalid password. When a valid Windows logon was found, a distinct response would be generated.
Recommendations
For versions prior to 5.12.5, upgrade to version 5.12.5 to resolve the issue.
As a temporary workaround for users unable to upgrade, consider rate-limiting API calls with software that sits in front of TGS in the HTTP pipeline, such as fail2ban.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tgstation