CVE-2023-34243: TGstation is a toolset to manage production BYOND servers. I..
Jun 8, 2023
Jun 15, 2023
TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attacker could discover their username by brute-forcing the login endpoint with an invalid password. When a valid Windows logon was found, a distinct response would be generated. This issue has been addressed in version 5.12.5. Users are advised to upgrade. Users unable to upgrade may be mitigated by rate-limiting API calls with software that sits in front of TGS in the HTTP pipeline such as fail2ban.
tgstation13» tgstation-server » *
CVSS base metrics
Learn from academy
What is API?
Types of APIs
GraphQL vs REST
REST vs SOAP
GET vs POST
PUT vs POST
GraphQL Authentication and Authorization
Swagger for API Documentation
Explore more from Akto
Be updated about everything related to API Security, new API vulnerabilities, industry news and product updates.
Discover and find tests from Akto's 100+ API Security test library. Choose your template or add a new template to start your API Security testing.
Check out Akto's product documentation for all information related to features and how to use them.