Use of Cache Containing Sensitive Information
CVE-2018-17107
Summary
In Tgstation tgstation-server 3.2.1.0 through 3.2.4.0, active logins would be cached, allowing subsequent logins to succeed with any username or password.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-524 - Use of Cache Containing Sensitive Information
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
Advisory Timeline
- Published