logo

GHSA-6rg3-8h8x-5xfv github.com/pterodactyl/wings

Package

Manager: go
Name: github.com/pterodactyl/wings
Vulnerable Version: =1.2.0 || >=1.2.0 <1.2.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

EPSS: N/A pctlN/A

Details

Unchecked hostname resolution could allow access to local network resources by users outside the local network ### Impact A newly implemented route allowing users to download files from remote endpoints was not properly verifying the destination hostname for user provided URLs. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible. This vulnerability requires valid authentication credentials and is therefore **not exploitable by unauthenticated users**. If you are running an instance for yourself or other trusted individuals this impact is unlikely to be of major concern to you. However, you should still upgrade for security sake. ### Patches Users should upgrade to the latest version of Wings. ### Workarounds There is no workaround available that does not involve modifying Panel or Wings code.

Metadata

Created: 2021-06-23T18:04:50Z
Modified: 2021-10-05T17:24:11Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-6rg3-8h8x-5xfv/GHSA-6rg3-8h8x-5xfv.json
CWE IDs: ["CWE-284", "CWE-441"]
Alternative ID: N/A
Finding: F039
Auto approve: 1