CVE-2025-68954 (CNNVD-202601-1117)
中文标题:
Pterodactyl 代码问题漏洞
英文标题:
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
漏洞描述
中文描述:
Pterodactyl是一款使用PHP、Nodejs和Go构建的开源游戏服务器管理面板。 Pterodactyl 1.11.11及之前版本存在代码问题漏洞,该漏洞源于当用户从服务器实例中移除或其SFTP文件访问权限更改时,未撤销活动的SFTP连接,可能导致用户在被撤销权限后仍能访问文件。
英文描述:
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability to be exploited. This issue is fixed in version 1.12.0.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| pterodactyl | panel | < 1.12.0 | - | - |
cpe:2.3:a:pterodactyl:panel:<__1.12.0:*:*:*:*:*:*:*
|
| pterodactyl | panel | * | - | - |
cpe:2.3:a:pterodactyl:panel:*:*:*:*:*:*:*:*
|
| pterodactyl | wings | * | - | - |
cpe:2.3:a:pterodactyl:wings:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-68954 |
2026-01-07 02:47:00 | 2026-01-12 02:12:32 |
| NVD | nvd_CVE-2025-68954 |
2026-01-09 03:00:07 | 2026-01-12 02:28:15 |
| CNNVD | cnnvd_CNNVD-202601-1117 |
2026-01-11 06:15:07 | 2026-01-12 02:38:12 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 1 -> 3
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202601-1117
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']