CVE-2023-25152 is a critical path traversal vulnerability affecting Pterodactyl Wings versions prior to v1.11.3 and v1.7.3. An authenticated attacker with an existing server allocation can exploit this to create arbitrary files and directories on the host system. This allows for potential resource allocation changes, container privilege escalation, or remote shell access via SSH key injection. Rated 8.8 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), it has a low attack complexity and high impact on confidentiality, integrity, and availability. There is no known active exploitation, public exploit code, or significant community discussion, and no workarounds exist; immediate patching is recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.3CPE matchmatch criteria | cpe:2.3:a:pterodactyl:wings:*:*:*:*:*:*:*:* | ||
1.11.0CPE matchmatch criteria | cpe:2.3:a:pterodactyl:wings:1.11.0:-:*:*:*:*:*:* | ||
1.11.1CPE matchmatch criteria | cpe:2.3:a:pterodactyl:wings:1.11.1:*:*:*:*:*:*:* | ||
1.11.2CPE matchmatch criteria | cpe:2.3:a:pterodactyl:wings:1.11.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.