CVE-2023-45814 is a use-after-free vulnerability affecting Bunkum, an open-source protocol-agnostic request server for custom game servers. The flaw stems from improper caching of authentication tokens, leading to cached tokens persisting beyond their intended lifetime. This can cause an exception when downstream projects remove expired tokens, resulting in an invalid use of IToken.User. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network attack vector with low attack complexity. While the impact is limited to information disclosure (C:L), it is restricted to specific endpoints under certain conditions, and the attacker cannot guarantee which token will be obtained. There is no evidence of active exploitation, and no exploit code is publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage are minimal. Users are advised to upgrade to Bunkum version 4.2.1, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0, < 4.2.1CPE matchmatch criteria | cpe:2.3:a:littlebigfresh:bunkum:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.