Wings Server Control Plane Vulnerability Affects Users of Pterodactyl Panel
CVE-2024-27102
10CRITICAL
What is CVE-2024-27102?
A vulnerability exists in Wings, the server control plane for the Pterodactyl Panel, affecting users running certain versions. This issue permits potential unauthorized access to the host system's files and directories, allowing an attacker with control over a server to read files outside of the designated sandbox. Although the specific extent of the impact remains unclear, the ability to access sensitive files could pose significant security risks. Mitigation necessitated a comprehensive overhaul of the server filesystem, resulting in a substantial patch size. Users are highly encouraged to upgrade to version 1.11.9 promptly, as no workarounds are available to address the vulnerability.
Affected Version(s)
wings < 1.11.9