The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade pterodactyl/panel
to version 1.11.8 or higher.
pterodactyl/panel is a game management panel.
Affected versions of this package are vulnerable to Cleartext Storage in a File or on Disk due to the logging of sensitive information in plain text when two-factor authentication is disabled. An attacker can potentially gain unauthorized access to user accounts.
Notes:
The attacker has to discover the account's email address or username separately.
Users who have ever disabled 2FA on a Panel should change their passwords and consider enabling 2FA if it was left disabled.
Panel administrators should consider clearing any access logs that may contain sensitive data, for Panels using NGINX, the access log is located at /var/log/nginx/pterodactyl.app-access.log
.