If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to.
Enabling the ignore_panel_config_updates
option or updating to the latest version of Wings are the only known workarounds.
https://github.com/pterodactyl/wings/commit/5415f8ae07f533623bd8169836dd7e0b933964de
{ "nvd_published_at": "2024-05-03T18:15:09Z", "cwe_ids": [ "CWE-552" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-03T20:28:10Z" }