Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1mZzUyLXhqZmMtOXJoOM4AAhdv
Pterodactyl vulnerable to 2FA Sniffing
Pterodactyl version 0.7.13 and lower - 2FA Sniffing
Users who have enabled 2FA protections on their account can unintentionally have their account's existence sniffed by malicious users who enter random credentials into the login fields.
Impact
Users who have enabled 2FA protections on their account can unintentionally have their account's existence sniffed by malicious users who enter random credentials into the login fields.
A logical mistake was made when the original code was written that would wait to verify the user's password until they had provided 2FA credentials if it was enabled on their account. However, because of this you could enter a bad password for a known email and determine if the account exists if you got redirected to a 2FA page.
For more information
If you have any questions or comments about this advisory please react out on Discord or email dane@[project name].io.
Permalink: https://github.com/advisories/GHSA-fg52-xjfc-9rh8JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mZzUyLXhqZmMtOXJoOM4AAhdv
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 2 years ago
Updated: almost 2 years ago
CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Percentage: 0.00158
EPSS Percentile: 0.52668
Identifiers: GHSA-fg52-xjfc-9rh8, CVE-2019-1020002
References:
- https://github.com/pterodactyl/panel/security/advisories/GHSA-vcm9-hx3q-qwj8
- https://nvd.nist.gov/vuln/detail/CVE-2019-1020002
- https://github.com/pterodactyl/panel/commit/092e7e79fff858ee026608c7dbccab165a67526f
- https://github.com/pterodactyl/panel/releases/tag/v0.7.14
- https://github.com/advisories/GHSA-fg52-xjfc-9rh8
Blast Radius: 1.0
Affected Packages
packagist:pterodactyl/panel
Dependent packages: 0Dependent repositories: 0
Downloads: 139 total
Affected Version Ranges: <= 0.7.13
Fixed in: 0.7.14
All affected versions: 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7, 0.7.8, 0.7.9, 0.7.10, 0.7.11, 0.7.12, 0.7.13
All unaffected versions: 0.7.14, 0.7.15, 0.7.16, 0.7.17, 0.7.18, 0.7.19, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.0, 1.2.1, 1.2.2, 1.3.0, 1.3.1, 1.3.2, 1.4.0, 1.4.1, 1.4.2, 1.5.0, 1.5.1, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.5, 1.6.6, 1.7.0, 1.8.0, 1.8.1, 1.9.0, 1.9.1, 1.9.2, 1.10.0, 1.10.1, 1.10.2, 1.10.3, 1.10.4, 1.11.0, 1.11.1, 1.11.2, 1.11.3, 1.11.4, 1.11.5, 1.11.6, 1.11.7, 1.11.8, 1.11.9, 1.11.10