PT-2021-24355 · Pterodactyl · Pterodactyl Wings

Trixterthetux

·

Published

2021-06-23

·

Updated

2025-02-21

·

CVE-2024-34068

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Pterodactyl Wings versions prior to 1.11.2
Description: An authenticated user with access to a game server can bypass previously implemented access control, potentially accessing resources on local networks that would otherwise be inaccessible. This issue allows malicious users to access internal endpoints of the node hosting Wings in the pull endpoint. The estimated number of potentially affected devices is not specified.
Recommendations: For versions prior to 1.11.2, upgrade to version 1.11.2 or later to resolve the issue. As a temporary workaround for users unable to upgrade, enable the api.disable remote download option.

Exploit

Fix

SSRF

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-34068
GHSA-6RG3-8H8X-5XFV
GHSA-QQ22-JJ8X-4WWV
GO-2024-2815

Affected Products

Pterodactyl Wings