U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-34068

Change History

New CVE Received by NIST 5/03/2024 2:15:09 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Added CWE

								
							
							
						
GitHub, Inc. CWE-284
Added CWE

								
							
							
						
GitHub, Inc. CWE-441
Added Description

								
							
							
						
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal endpoints of the node hosting Wings in the pull endpoint. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible. This issue has been addressed in version 1.11.2 and users are advised to upgrade. Users unable to upgrade may enable the `api.disable_remote_download` option as a workaround. 
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/pterodactyl/wings/commit/c152e36101aba45d8868a9a0eeb890995e8934b8 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/pterodactyl/wings/security/advisories/GHSA-6rg3-8h8x-5xfv [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/pterodactyl/wings/security/advisories/GHSA-qq22-jj8x-4wwv [No types assigned]