Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
Published Nov 17, 2021
4.3
MEDIUMCVSS 3.1
EPSS 0.39%
Description
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node auto-deployment token. At no point would any data be exposed to the malicious user, this would simply trigger email spam to an administrative user, or generate a single auto-deployment token unexpectedly. This token is not revealed to the malicious user, it is simply created unexpectedly in the system. This has been addressed in release `1.6.6`. Users may optionally manually apply the fixes released in v1.6.6 to patch their own systems.
Affected products
-
Affected
- < 1.6.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Pterodactyl | Panel | unknown | Affected
|
- < 1.6.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2407 Advisory
- https://github.com/advisories/GHSA-wwgq-9jhf-qgw6 Advisory
- https://github.com/pterodactyl/panel/commit/bf9cbe2c6d5266c6914223e067c56175de7fc3a5 x_refsource_MISCPatchThird Party Advisory
- https://github.com/pterodactyl/panel/security/advisories/GHSA-wwgq-9jhf-qgw6 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-41273
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2407 | Advisory | |
| https://github.com/advisories/GHSA-wwgq-9jhf-qgw6 | Advisory | |
| https://github.com/pterodactyl/panel/commit/bf9cbe2c6d5266c6914223e067c56175de7fc3a5 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/pterodactyl/panel/security/advisories/GHSA-wwgq-9jhf-qgw6 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-41273 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub