CVE-2024-34066: Arbitrary File Write/Read in Pterodactyl wings

Published May 3, 2024
·
Updated

Impact

If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to.

Workarounds

Enabling the ignorepanelconfigupdates option or updating to the latest version of Wings are the only known workarounds.

Patches

https://github.com/pterodactyl/wings/commit/5415f8ae07f533623bd8169836dd7e0b933964de

Other sources

Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has been addressed in version 1.11.12 and users are advised to upgrade. Users unable to upgrade may enable the ignorepanelconfigupdates option as a workaround.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/pterodactyl/wings<1.11.12
1.11.12
pterodactyl wings<1.11.2

Event History

May 3, 2024
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyAffected Software
Advisory Published
via GitHub·08:28 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-34066?

CVE-2024-34066 has a high severity rating due to the potential for arbitrary file read and write access if the Wings token is leaked.

2

How do I fix CVE-2024-34066?

To fix CVE-2024-34066, ensure that your Pterodactyl Wings installation is updated to version 1.11.13 or higher.

3

What is the impact of CVE-2024-34066?

The impact of CVE-2024-34066 is that leaking the Wings token allows attackers to access and manipulate files on the associated node.

4

Which versions of Pterodactyl Wings are affected by CVE-2024-34066?

CVE-2024-34066 affects Pterodactyl Wings versions up to 1.11.12 and 1.11.2.

5

Can I mitigate CVE-2024-34066 without upgrading?

Yes, you can mitigate CVE-2024-34066 by enabling the 'ignore_panel_config_update' option in the Wings configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203