CVE Feed

    Dashboard / CVE / CVE-2023-32687

    CVE-2023-32687

    tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bots permission can read chat bot connections strings without the associated permission. This issue is patched in version 5.12.1. As a workaround, remove the list chat bots permission from users that should not have the ability to view connection strings. Invalidate any credentials previously stored for safety.

    Published:May 29, 2023
    Last Modified:Jan 13, 2025
    EPS:May 29, 2023
    EPSS Score:0.00157
    CVSS Score:7.7

    Affected Products

    Vendor
    Tgstation13
    Product
    Tgstation-server

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High