Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj6m-r8jc-2gp7

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings

Impact

All versions of Pterodactyl Wings preior to 1.4.4 are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding.

Patches

Users should upgrade to 1.4.4.

Workarounds

There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.

For more information

If you have any questions or comments about this advisory:

  • Contact us on Discord
  • Email us at dane ät pterodactyl dot io

Пакеты

Наименование

github.com/pterodactyl/wings

go
Затронутые версииВерсия исправления

< 1.4.4

1.4.4

EPSS

Процентиль: 17%
0.00054
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-405
CWE-770

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding. Users should upgrade to `1.4.4` to mitigate the issue. There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.

EPSS

Процентиль: 17%
0.00054
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-405
CWE-770