CVE-2025-21611
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 6, 2025
CWE ID 285
Summary
CVE-2025-21611 is a vulnerability affecting the tgstation-server software used for BYOND server management. Before version 6.12.3, the authorization process for API methods was incorrectly implemented with an OR logic instead of AND logic. Consequently, enabled users could gain access to some authorized actions beyond their assigned permissions. However, the WriteUsers right remains unaffected, preventing users from permanently elevating their account permissions. The vulnerability was addressed in the release of tgstation-server-v6.12.3.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.