CVE-2021-41176
pterodactyl/panel CSRF allowing an external page to trigger a user logout event
0.0
NONE
CVSS 3.1
EPSS 0.50%
描述
### Impact A malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This requires a targeted attack against a specific Panel instance, and serves only to sign a user out. **No user details are leaked, nor is any user data affected, this is simply an annoyance at worst.** ### Patches None. ### Workarounds None. ### For more information If you have any questions or comments about this advisory please contact `Tactical Fish#8008` on Discord, or email `dane@pterodactyl.io`.
如何修補 CVE-2021-41176
要修補 CVE-2021-41176,請將受影響套件升級到下列已修補版本。
- —升級至 1.6.3 或更新版本
CVE-2021-41176 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 1.0.0, < 1.6.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | NONE0.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N |