GHSA-jj6m-r8jc-2gp7

Suggest an improvement
Source
https://github.com/advisories/GHSA-jj6m-r8jc-2gp7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-jj6m-r8jc-2gp7/GHSA-jj6m-r8jc-2gp7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jj6m-r8jc-2gp7
Aliases
Related
Published
2021-06-23T18:03:18Z
Modified
2024-08-21T15:58:40.865263Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Details

Impact

All versions of Pterodactyl Wings preior to 1.4.4 are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding.

Patches

Users should upgrade to 1.4.4.

Workarounds

There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.

For more information

If you have any questions or comments about this advisory: * Contact us on Discord * Email us at dane ät pterodactyl dot io

Database specific
{
    "nvd_published_at": "2021-06-22T20:15:00Z",
    "github_reviewed_at": "2021-06-22T15:43:57Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-405",
        "CWE-770"
    ]
}
References

Affected packages

Go / github.com/pterodactyl/wings

Package

Name
github.com/pterodactyl/wings
View open source insights on deps.dev
Purl
pkg:golang/github.com/pterodactyl/wings

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4