PT-2024-25677 · Pterodactyl · Pterodactyl Wings
Trixterthetux
·
Published
2024-05-03
·
Updated
2025-02-21
·
CVE-2024-34066
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pterodactyl Wings versions prior to 1.11.12
Description
The issue allows an attacker to gain arbitrary file write and read access on a node if the Wings token is leaked, either by viewing the node configuration or posting it accidentally somewhere.
Recommendations
For versions prior to 1.11.12, update to version 1.11.12 to resolve the issue.
As a temporary workaround for users unable to upgrade, enable the
ignore panel config updates option.Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pterodactyl Wings