CVE-2020-16136
TG Station Server vulnerability analysis and mitigation

Overview

In tgstation-server versions 4.4.0 and 4.4.1, a directory traversal vulnerability was discovered that allowed authenticated users with permission to download logs to access any file on the server machine that was accessible by the server process owner through the /Administration/Logs/ requests using '../' sequences (NVD, GitHub Advisory).

Technical details

The vulnerability (CVE-2020-16136) is a directory traversal issue that affects the log downloading functionality. While the attacker needs to be authenticated and have specific permissions to exploit this vulnerability, they can use '../' sequences in /Administration/Logs/ requests to access files outside the intended directory. The vulnerability has a CVSS v3.1 base score of 7.7 (High), with the attack vector being Network, low attack complexity, requiring low privileges, and no user interaction needed (GitHub Advisory).

Impact

The primary impact of this vulnerability is unauthorized access to files on the server machine that are accessible by the server process owner. While the attacker cannot enumerate files, they can still access known files outside the intended log directory, potentially exposing sensitive information (GitHub Advisory).

Exploitability

The vulnerability requires an authenticated user with permission to download logs. While this limits the potential attackers, the actual exploitation is straightforward using '../' sequences in the request paths (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version 4.4.2. As a workaround, administrators can remove the 'Edit Users' and 'Download Server Logs' permissions from all users that should not have access to the host filesystem (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related TG Station Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-41799CRITICAL9.9
  • C# logoC#
  • cpe:2.3:a:tgstation13:tgstation-server
NoYesJul 29, 2024
CVE-2025-21611HIGH8.8
  • TG Station Server logoTG Station Server
  • cpe:2.3:a:tgstation13:tgstation-server
NoYesJan 06, 2025
CVE-2023-33198HIGH7.5
  • TG Station Server logoTG Station Server
  • cpe:2.3:a:tgstation13:tgstation-server
NoYesMay 30, 2023
CVE-2023-32687MEDIUM6.5
  • TG Station Server logoTG Station Server
  • cpe:2.3:a:tgstation13:tgstation-server
NoYesMay 29, 2023
CVE-2023-34243MEDIUM5.3
  • TG Station Server logoTG Station Server
  • cpe:2.3:a:tgstation13:tgstation-server
NoYesJun 08, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management