PT-2021-24355 · Pterodactyl · Pterodactyl Wings
Trixterthetux
·
Published
2021-06-23
·
Updated
2025-02-21
·
CVE-2024-34068
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Pterodactyl Wings versions prior to 1.11.2
Description:
An authenticated user with access to a game server can bypass previously implemented access control, potentially accessing resources on local networks that would otherwise be inaccessible. This issue allows malicious users to access internal endpoints of the node hosting Wings in the pull endpoint. The estimated number of potentially affected devices is not specified.
Recommendations:
For versions prior to 1.11.2, upgrade to version 1.11.2 or later to resolve the issue.
As a temporary workaround for users unable to upgrade, enable the
api.disable remote download option.Exploit
Fix
SSRF
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pterodactyl Wings