Low severityNVD Advisory· Published Oct 25, 2021· Updated Aug 4, 2024
logout CSRF in Pterodactyl Panel
CVE-2021-41176
Description
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This requires a targeted attack against a specific Panel instance, and serves only to sign a user out. No user details are leaked, nor is any user data affected, this is simply an annoyance at worst. This is fixed in version 1.6.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pterodactyl/panelPackagist | >= 1.0.0, < 1.6.3 | 1.6.3 |
Affected products
2- Range: >= 1.0.0 < 1.6.3
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-m49f-hcxp-6hm6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-41176ghsaADVISORY
- github.com/pterodactyl/panel/commit/45999ba4ee1b2dcb12b4a2fa2cedfb6b5d66fac2ghsax_refsource_MISCWEB
- github.com/pterodactyl/panel/releases/tag/v1.6.3ghsax_refsource_MISCWEB
- github.com/pterodactyl/panel/security/advisories/GHSA-m49f-hcxp-6hm6ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.