CVE-2023-32687: Insufficiently Protected ChatBot Credentials in tgstation-server
tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bots permission can read chat bot connections strings without the associated permission. This issue is patched in version 5.12.1. As a workaround, remove the list chat bots permission from users that should not have the ability to view connection strings. Invalidate any credentials previously stored for safety.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-32687?
CVE-2023-32687 is a vulnerability in tgstation-server that allows instance users with the list chat bots permission to read chat bot connection strings without the associated permission.
How severe is CVE-2023-32687?
CVE-2023-32687 has a severity rating of 6.5 (high).
Which software versions are affected by CVE-2023-32687?
Versions of tgstation-server prior to 5.12.1 (starting from 4.7.0) are affected by CVE-2023-32687.
How can I fix CVE-2023-32687?
To fix CVE-2023-32687, update tgstation-server to version 5.12.1 or later.
Is there a workaround for CVE-2023-32687?
As a workaround for CVE-2023-32687, you can remove the list chat bots permission for instance users.