HIGHNuGet

tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users

tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users

CVE-2024-41799Published 2 years agoUpdated 5 days agoSource: OSV

Affected packages

  • Tgstation.Server.Api4.0.0 → 6.8.0
  • Tgstation.Server.Host4.0.0 → 6.8.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users | HackTribune