—
GO-2024-2815
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings
Quick fix
GO-2024-2815 — github.com/pterodactyl/wings: upgrade to the fixed version with the command below.
go get github.com/pterodactyl/wings@v1.11.12Details
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull in github.com/pterodactyl/wings
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/pterodactyl/wings
Introduced in:
0Fixed in: 1.11.12Fix
go get github.com/pterodactyl/wings@v1.11.12References
- https://github.com/pterodactyl/wings/security/advisories/GHSA-qq22-jj8x-4wwv[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-34068[ADVISORY]
- https://github.com/pterodactyl/wings/commit/c152e36101aba45d8868a9a0eeb890995e8934b8[FIX]
- https://github.com/pterodactyl/wings/security/advisories/GHSA-6rg3-8h8x-5xfv[WEB]