PT-2021-19865 · Unknown · Pterodactyl Wings

Dane Everitt

·

Published

2021-06-22

·

Updated

2024-08-21

·

CVE-2021-32699

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pterodactyl Wings versions prior to 1.4.4
Description The issue concerns system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended, causing downstream impacts to other clients on the same hardware, and eventually leading to the physical server stopping its response.
Recommendations For versions prior to 1.4.4, upgrade to version 1.4.4 to mitigate the issue. As a temporary workaround for customized versions, manually set a PID limit for containers created.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2021-32699
GHSA-JJ6M-R8JC-2GP7
GO-2022-0919

Affected Products

Pterodactyl Wings