PT-2024-25677 · Pterodactyl · Pterodactyl Wings

Trixterthetux

·

Published

2024-05-03

·

Updated

2025-02-21

·

CVE-2024-34066

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pterodactyl Wings versions prior to 1.11.12
Description The issue allows an attacker to gain arbitrary file write and read access on a node if the Wings token is leaked, either by viewing the node configuration or posting it accidentally somewhere.
Recommendations For versions prior to 1.11.12, update to version 1.11.12 to resolve the issue. As a temporary workaround for users unable to upgrade, enable the ignore panel config updates option.

Exploit

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-34066
GHSA-GQMF-JQGV-V8FW
GO-2024-2814

Affected Products

Pterodactyl Wings