Wings Server Control Plane Vulnerability Affects Users of Pterodactyl Panel
CVE-2024-27102

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
13 March 2024

What is CVE-2024-27102?

A vulnerability exists in Wings, the server control plane for the Pterodactyl Panel, affecting users running certain versions. This issue permits potential unauthorized access to the host system's files and directories, allowing an attacker with control over a server to read files outside of the designated sandbox. Although the specific extent of the impact remains unclear, the ability to access sensitive files could pose significant security risks. Mitigation necessitated a comprehensive overhaul of the server filesystem, resulting in a substantial patch size. Users are highly encouraged to upgrade to version 1.11.9 promptly, as no workarounds are available to address the vulnerability.

Affected Version(s)

wings < 1.11.9

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.