github.com
https://github.com/tgstation/tgstation-server/pull/1493 CVE-2023-33198
MEDIUM
Incorrectly Specified Chat Message Destinations in tgstation-server and DreamMaker API
Record summary
CVE-2023-33198 has a selected CVSS score of 6.1 (medium).
Description
tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache can possibly be poisoned by a tgstation-server (TGS) restart and reattach. This can result in sending chat messages to one of any of the configured IRC or Discord channels for the instance on enabled chat bots. This lasts until the instance's chat channels are updated in TGS or DreamDaemon is restarted. TGS chat commands are unaffected, custom or otherwise.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tgstation-serverBrowse tgstation / tgstation-server | CVE List | >= 4.0.0, < 5.12.2 | affected |
References
3github.com
https://github.com/tgstation/tgstation-server/releases/tag/tgstation-server-v5.12.2 github.comConfirmation
https://github.com/tgstation/tgstation-server/security/advisories/GHSA-p2xj-w57r-6f5m