Description
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has been addressed in version 1.11.12 and users are advised to upgrade. Users unable to upgrade may enable the `ignore_panel_config_updates` option as a workaround.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1631 | Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has been addressed in version 1.11.12 and users are advised to upgrade. Users unable to upgrade may enable the `ignore_panel_config_updates` option as a workaround. |
Github GHSA |
GHSA-gqmf-jqgv-v8fw | Pterodactyl Wings vulnerable to Arbitrary File Write/Read |
References
History
Fri, 21 Feb 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pterodactyl
Pterodactyl wings |
|
| CPEs | cpe:2.3:a:pterodactyl:wings:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pterodactyl
Pterodactyl wings |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:42:59.879Z
Reserved: 2024-04-30T06:56:33.381Z
Link: CVE-2024-34066
Updated: 2024-08-02T02:42:59.879Z
Status : Analyzed
Published: 2024-05-03T18:15:09.363
Modified: 2025-02-21T15:15:38.680
Link: CVE-2024-34066
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA