VDB
Sign up
HIGH

GHSA-hvm9-wc8j-mgrc

TShock Security Escalation Exploit

Quick fix

GHSA-hvm9-wc8j-mgrc — TShock: upgrade to the fixed version with the command below.

dotnet add package TShock --version 5.2.1

Details

### Impact An issue with the way OTAPI manages client connections results in stale UUIDs remaining on `RemoteClient` instances after a player disconnects.

Because of this, if the following conditions are met a player may assume the login state of a previously connected player: 1. The server has UUID login enabled 2. An authenticated player disconnects 3. A subsequent player connects with a modified client that does not send the `ClientUUID#68` packet during connection 4. The server assigns the same `RemoteClient` object that belonged to the originally authenticated player to the newly connected player

### Patches TShock 5.2.1 hotfixes this issue. A more robust fix will be made to OTAPI itself.

### Workarounds Implement a RemoteClient reset event handler in a plugin like so: ```csharp public override void Initialize() { On.Terraria.RemoteClient.Reset += RemoteClient_Reset; }

private static void RemoteClient_Reset(On.Terraria.RemoteClient.orig_Reset orig, RemoteClient client) { client.ClientUUID = null; orig(client); } ```

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/TShock
Introduced in: 4.3.21Fixed in: 5.2.1
Fixdotnet add package TShock --version 5.2.1

References