Skip to main content

Use of Cache Containing Sensitive Information

CVE-2018-17107

Severity High
Score 9.8/10

Summary

In Tgstation tgstation-server 3.2.1.0 through 3.2.4.0, active logins would be cached, allowing subsequent logins to succeed with any username or password.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-524 - Use of Cache Containing Sensitive Information

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Advisory Timeline

  • Published