Server-side Request Forgery (SSRF)
Affecting github.com/pterodactyl/wings/router/downloader package, versions <1.2.1
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
github.com/pterodactyl/wings/router/downloader is a Wings is Pterodactyl's server control plane, built for the rapidly changing gaming industry and designed to be highly performant and secure.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF). It is possible for a malicious user to scan or access resources on the local network.
Remediation
Upgrade github.com/pterodactyl/wings/router/downloader
to version 1.2.1 or higher.
References
CVSS Score
8.6
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityLow
-
AvailabilityLow
- Credit
- Unknown
- CWE
- CWE-918
- Snyk ID
- SNYK-GOLANG-GITHUBCOMPTERODACTYLWINGSROUTERDOWNLOADER-1056514
- Disclosed
- 07 Jan, 2021
- Published
- 07 Jan, 2021