SCA: security update for pterodactyl/panel (GHSA-5vfx-8w6m-h3v4)

high Tenable Cloud Security Plugin ID 411030

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious
user can modify the contents of a `confirmation_token` input during the two-factor authentication process
to reference a cache value not associated with the login attempt. In rare cases this can allow a malicious
actor to authenticate as a random user in the Panel. The malicious user must target an account with two-
factor authentication enabled, and then must provide a correct two-factor authentication token before
being authenticated as that user. Due to a validation flaw in the logic handling user authentication
during the two-factor authentication process a malicious user can trick the system into loading
credentials for an arbitrary user by modifying the token sent to the server. This authentication flaw is
present in the `LoginCheckpointController@__invoke` method which handles two-factor authentication for a
user. This controller looks for a request input parameter called `confirmation_token` which is expected to
be a 64 character random alpha-numeric string that references a value within the Panel's cache containing
a `user_id` value. This value is then used to fetch the user that attempted to login, and lookup their
two-factor authentication token. Due to the design of this system, any element in the cache that contains
only digits could be referenced by a malicious user, and whatever value is stored at that position would
be used as the `user_id`. There are a few different areas of the Panel that store values into the cache
that are integers, and a user who determines what those cache keys are could pass one of those keys which
would cause this code pathway to reference an arbitrary user. At its heart this is a high-risk login
bypass vulnerability. However, there are a few additional conditions that must be met in order for this to
be successfully executed, notably: 1.) The account referenced by the malicious cache key must have two-
factor authentication enabled. An account without two-factor authentication would cause an exception to be
triggered by the authentication logic, thusly exiting this authentication flow. 2.) Even if the malicious
user is able to reference a valid cache key that references a valid user account with two-factor
authentication, they must provide a valid two-factor authentication token. However, due to the design of
this endpoint once a valid user account is found with two-factor authentication enabled there is no rate-
limiting present, thusly allowing an attacker to brute force combinations until successful. This leads to
a third condition that must be met: 3.) For the duration of this attack sequence the cache key being
referenced must continue to exist with a valid `user_id` value. Depending on the specific key being used
for this attack, this value may disappear quickly, or be changed by other random user interactions on the
Panel, outside the control of the attacker. In order to mitigate this vulnerability the underlying
authentication logic was changed to use an encrypted session store that the user is therefore unable to
control the value of. This completely removed the use of a user-controlled value being used. In addition,
the code was audited to ensure this type of vulnerability is not present elsewhere. (CVE-2021-41129)

See Also

https://github.com/advisories/GHSA-5vfx-8w6m-h3v4

Plugin Details

Severity: High

ID: 411030

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-41129

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/4/2021

Vulnerability Publication Date: 10/4/2021

Reference Information

CVE: CVE-2021-41129