GHSA-hr7j-63v7-vj7g: Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
Deleting a user account with SFTP access or changing the user’s password does not immediately terminate existing SFTP sessions, allowing continued filesystem access after credentials are revoked. This can result in unintended and unauthorized access to server files even after administrators believe access has been fully invalidated.
References
Code Behaviors & Features
Detect and mitigate GHSA-hr7j-63v7-vj7g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →