Use of Cache Containing Sensitive Information Affecting tgserviceinterface package, versions [3.2.1.0, 3.2.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (66th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-TGSERVICEINTERFACE-5673801
  • published11 Jun 2023
  • disclosed13 May 2022
  • creditUnknown

Introduced: 13 May 2022

CVE-2018-17107  (opens in a new tab)
CWE-524  (opens in a new tab)

How to fix?

Upgrade TGServiceInterface to version 3.2.6 or higher.

Overview

TGServiceInterface is a production scale tool for BYOND server management.

Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information due to active logins being cached, allowing subsequent logins to succeed with any username or password.

CVSS Scores

version 3.1