
Cloud Vulnerability DB
A community-led vulnerabilities database
Due to a bug in ASF (ArchiSteamFarm) code, the POST /Api/ASF ASF API endpoint responsible for updating global ASF config incorrectly removed IPCPassword from the resulting config when the caller did not specify it explicitly. This vulnerability was discovered in July 2021 and affected versions prior to 5.1.2.4. The vulnerability is tracked as CVE-2021-32794 and has been assigned a CVSS score of 6.8 (Moderate) (GitHub Advisory).
The vulnerability occurred when updating the global ASF configuration through the API endpoint. When a user made changes to the global config without explicitly specifying the IPCPassword, the system would incorrectly remove the password instead of preserving it. This behavior was specific to the IPCPassword property, while other sensitive properties like SteamLogin or SteamPassword remained unaffected (GitHub Advisory).
The removal of IPCPassword could expose the IPC interface to unauthorized access. While the vulnerability required an initially authorized user to trigger the bug, it could lead to security risks by accidentally removing the authentication mechanism protecting the IPC interface. The issue primarily affected users who were using ASF on VPS with IPC server behind a reverse proxy (GitHub Advisory, Steam Discussion).
The vulnerability could not be exploited remotely without prior authorization. An attacker would need to have valid authentication credentials to trigger the bug. The issue was particularly concerning for users who were using ASF-ui's global config update functionality (GitHub PR).
The issue was patched in ASF version 5.1.2.4 and later versions. Users are recommended to manually verify that IPCPassword is specified after updating. For those unable to upgrade, workarounds include refraining from using POST /Api/ASF endpoint, not using ASF-ui global config update functionality, or manually resetting IPCPassword after any configuration changes. By default, ASF is configured to allow IPC access from localhost only, which limits the vulnerability's scope (GitHub Advisory).
The issue was initially reported in the Steam community forums, where users reported instances of inventory theft potentially linked to this vulnerability. The development team responded promptly by investigating the reports and implementing fixes (Steam Discussion).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."