Cleartext Storage in a File or on Disk Affecting pterodactyl/panel package, versions <1.11.8


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-PTERODACTYLPANEL-8303776
  • published25 Oct 2024
  • disclosed24 Oct 2024
  • creditPebbleHost

Introduced: 24 Oct 2024

CVE-2024-49762  (opens in a new tab)
CWE-313  (opens in a new tab)

How to fix?

Upgrade pterodactyl/panel to version 1.11.8 or higher.

Overview

pterodactyl/panel is a game management panel.

Affected versions of this package are vulnerable to Cleartext Storage in a File or on Disk due to the logging of sensitive information in plain text when two-factor authentication is disabled. An attacker can potentially gain unauthorized access to user accounts.

Notes:

  1. The attacker has to discover the account's email address or username separately.

  2. Users who have ever disabled 2FA on a Panel should change their passwords and consider enabling 2FA if it was left disabled.

  3. Panel administrators should consider clearing any access logs that may contain sensitive data, for Panels using NGINX, the access log is located at /var/log/nginx/pterodactyl.app-access.log.

CVSS Scores

version 4.0
version 3.1