CVE-2023-25152
published 2023-02-08CVE-2023-25152: Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.68%
47.8th percentile
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged mode, or potentially add ssh authorized keys to allow the attacker access to a remote shell on the target machine. In order to use this exploit, an attacker must have an existing "server" allocated and controlled by the Wings Daemon. This vulnerability has been resolved in version `v1.11.3` of the Wings Daemon, and has been back-ported to the 1.7 release series in `v1.7.3`. Anyone running `v1.11.x` should upgrade to `v1.11.3` and anyone running `v1.7.x` should upgrade to `v1.7.3`. There are no known workarounds for this vulnerability.
### Workarounds
None at this time.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | pterodactyl_wings | >= 0 < 1.7.3 | 1.7.3 |
| github.com | pterodactyl_wings | >= 1.11.0 < 1.11.3 | 1.11.3 |
| mozilla | thunderbird | >= 0 < 1:102.9.0+build1-0ubuntu0.18.04.1 | 1:102.9.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.9.0+build1-0ubuntu0.20.04.1 | 1:102.9.0+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.9.0+build1-0ubuntu0.22.04.1 | 1:102.9.0+build1-0ubuntu0.22.04.1 |
| pterodactyl | wings | < 1.7.3 | 1.7.3 |
| pterodactyl | wings | — | — |
| pterodactyl | wings | — | — |
| pterodactyl | wings | — | — |
| pterodactyl | wings | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
osv·2024-08-20
CVE-2023-25152 Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following in github.com/pterodactyl/wings
OSV
thunderbird vulnerabilities
osv·2023-03-27·CVSS 8.8
CVE-2023-25152 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-25152, CVE-2023-28162,
CVE-2023-28176)
Lukas Bernhard discovered that Thunderbird did not properly manage memory
when invalidating JIT code while following an iterator. An attacker could
potentially exploits this issue to cause a denial of service.
(CVE-2023-25751)
Luan Herrera discovered that Thunderbird did not properly manage
cross-origin iframe when dragging a URL. An attacker could potentially
exploit this issue to perform sp
OSV
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
osv·2023-02-08
CVE-2023-25152 [HIGH] Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
### Impact
This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can be used to create new files and on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged mode, or potentially add ssh authorized keys to allow the attacker access to a remote shell on the target machine.
In order to use this exploit, an attacker must have an existing "server" allocated and controlled by Wings. Information on how the exploitation of this vulnerability works will be released on February 24th, 2023 in North America.
### Patches
This vulnerability has been resolved in version `v1.11.3` of Wings, and has
GHSA
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
ghsa·2023-02-08
CVE-2023-25152 [HIGH] CWE-59 Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
### Impact
This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can be used to create new files and on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged mode, or potentially add ssh authorized keys to allow the attacker access to a remote shell on the target machine.
In order to use this exploit, an attacker must have an existing "server" allocated and controlled by Wings. Information on how the exploitation of this vulnerability works will be released on February 24th, 2023 in North America.
### Patches
This vulnerability has been resolved in version `v1.11.3` of Wings, and has
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2023-03-27·CVSS 8.4
CVE-2023-25752 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-25152, CVE-2023-28162,
CVE-2023-28176)
Lukas Bernhard discovered that Thunderbird did not properly manage memory
when invalidating JIT code while following an iterator. An attacker could
potentially exploits this issue to cause a denial of service.
(CVE-2023-25751)
Luan Herrera discovered that Thunderbird did not properly manage
cross-origin iframe when dragging a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/pterodactyl/wings/commit/dac9685298c3c1c49b3109fa4241aa88272b9f14https://github.com/pterodactyl/wings/security/advisories/GHSA-p8r3-83r8-jwj5https://github.com/pterodactyl/wings/commit/dac9685298c3c1c49b3109fa4241aa88272b9f14https://github.com/pterodactyl/wings/security/advisories/GHSA-p8r3-83r8-jwj5
2023-02-08
Published