CVE-2018-17107: Critical severity tgstation 13 vulnerability
Published Sep 24, 2018
·Updated
In Tgstation tgstation-server 3.2.4.0 through 3.2.1.0 (fixed in 3.2.5.0), active logins would be cached, allowing subsequent logins to succeed with any username or password.
Affected Software
1 affected component
Tgstation13 Tgstation-server>=3.2.1.0<3.2.5.0
Event History
Sep 24, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17107?
The severity of CVE-2018-17107 is critical, with a CVSS score of 9.8.
2
What is the affected software for CVE-2018-17107?
The affected software for CVE-2018-17107 is Tgstation tgstation-server versions 3.2.4.0 through 3.2.1.0.
3
How can active logins be cached in tgstation-server?
Active logins can be cached in tgstation-server versions 3.2.4.0 through 3.2.1.0, allowing subsequent logins to succeed with any username or password.
4
What is the fix for CVE-2018-17107?
The fix for CVE-2018-17107 is available in Tgstation tgstation-server version 3.2.5.0.
5
Where can I find more information about CVE-2018-17107?
More information about CVE-2018-17107 can be found at the following reference: https://github.com/tgstation/tgstation-server/issues/690