
Cloud Vulnerability DB
A community-led vulnerabilities database
In tgstation-server versions 4.4.0 and 4.4.1, a directory traversal vulnerability was discovered that allowed authenticated users with permission to download logs to access any file on the server machine that was accessible by the server process owner through the /Administration/Logs/ requests using '../' sequences (NVD, GitHub Advisory).
The vulnerability (CVE-2020-16136) is a directory traversal issue that affects the log downloading functionality. While the attacker needs to be authenticated and have specific permissions to exploit this vulnerability, they can use '../' sequences in /Administration/Logs/ requests to access files outside the intended directory. The vulnerability has a CVSS v3.1 base score of 7.7 (High), with the attack vector being Network, low attack complexity, requiring low privileges, and no user interaction needed (GitHub Advisory).
The primary impact of this vulnerability is unauthorized access to files on the server machine that are accessible by the server process owner. While the attacker cannot enumerate files, they can still access known files outside the intended log directory, potentially exposing sensitive information (GitHub Advisory).
The vulnerability requires an authenticated user with permission to download logs. While this limits the potential attackers, the actual exploitation is straightforward using '../' sequences in the request paths (GitHub Advisory).
The vulnerability was patched in version 4.4.2. As a workaround, administrators can remove the 'Edit Users' and 'Download Server Logs' permissions from all users that should not have access to the host filesystem (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."