VDB
Sign up
MEDIUM6.5

GHSA-rgmp-4873-r683

Pterodactyl TOTPs can be reused during validity window

Quick fix

GHSA-rgmp-4873-r683 — pterodactyl/panel: upgrade to the fixed version with the command below.

composer require pterodactyl/panel:^1.12.0

Details

### Summary When a user signs into an account with 2FA enabled they are prompted to enter a token. When that token is used, it is not sufficiently marked as used in the system allowing an attacker that intercepts that token to then use it in addition to a known username/password during the token validity window.

This vulnerability requires that an attacker already be in possession of a valid username and password combination, and intercept a valid 2FA token (for example, during a screen share). The token must then be provided in addition to the username and password during the limited token validity window. The validity window is ~60 seconds as the Panel allows at most one additional window to the current one, each window being 30 seconds.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/pterodactyl/panel
Introduced in: 0Fixed in: 1.12.0
Fixcomposer require pterodactyl/panel:^1.12.0

References