SCA: security update for github.com/pterodactyl/wings (GHSA-66p8-j459-rq63)

high Tenable Cloud Security Plugin ID 411251

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and
directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5`
to overwrite files on the host system. In order to use this exploit, an attacker must have an existing
"server" allocated and controlled by Wings. This vulnerability has been resolved in version `v1.11.4` of
Wings, and has been back-ported to the 1.7 release series in `v1.7.4`. Anyone running `v1.11.x` should
upgrade to `v1.11.4` and anyone running `v1.7.x` should upgrade to `v1.7.4`. There are no known
workarounds for this issue. (CVE-2023-25168)

See Also

https://github.com/advisories/GHSA-66p8-j459-rq63

Plugin Details

Severity: High

ID: 411251

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.8

Percentile: 97.07

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:N/AC:H/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2023-25168

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/10/2023

Vulnerability Publication Date: 2/8/2023

Reference Information

CVE: CVE-2023-25168

cwe: CWE-59