Pterodactyl Wings vulnerable to Arbitrary File Write/Read
Description
Published by the National Vulnerability Database
May 3, 2024
Published to the GitHub Advisory Database
May 3, 2024
Reviewed
May 3, 2024
Last updated
May 3, 2024
Impact
If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to.
Workarounds
Enabling the
ignore_panel_config_updates
option or updating to the latest version of Wings are the only known workarounds.Patches
pterodactyl/wings@5415f8a
References