-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from exposed configuration fields in struct definitions (not specific functions) that allowed programmatic updates via API when deserializing JSON input. The commit adds json:"-" tags to sensitive fields in configuration structs (ApiConfiguration.DisableRemoteDownload, SystemConfiguration fields, Configuration.PanelLocation) to prevent serialization/deserialization. While these structs are used by configuration handling logic, the vulnerability manifests at the data structure/API interaction layer rather than specific function implementations. No concrete functions handling the deserialization or config updates are shown in the provided diff to analyze directly.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/pterodactyl/wings | go | < 1.11.12 | 1.11.12 |
Ongoing coverage of React2Shell