Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/pterodactyl/wings
  4. ›
  5. GMS-2021-178

GMS-2021-178: Unchecked hostname resolution could allow access to local network resources by users outside the local network

June 23, 2021 (updated October 5, 2021)

Impact

A newly implemented route allowing users to download files from remote endpoints was not properly verifying the destination hostname for user provided URLs. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible.

This vulnerability requires valid authentication credentials and is therefore not exploitable by unauthenticated users. If you are running an instance for yourself or other trusted individuals this impact is unlikely to be of major concern to you. However, you should still upgrade for security sake.

Patches

Users should upgrade to the latest version of Wings.

Workarounds

There is no workaround available that does not involve modifying Panel or Wings code.

References

  • github.com/advisories/GHSA-6rg3-8h8x-5xfv
  • github.com/pterodactyl/wings/security/advisories/GHSA-6rg3-8h8x-5xfv

Code Behaviors & Features

Detect and mitigate GMS-2021-178 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

Version 1.2.0

Fixed versions

  • 1.2.1

Solution

Upgrade to version 1.2.1 or above.

Source file

go/github.com/pterodactyl/wings/GMS-2021-178.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:59 +0000.