Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Moderate severity
GitHub Reviewed
Published
Jun 21, 2021
in
pterodactyl/wings
•
Updated Jan 29, 2023
Description
Reviewed
Jun 22, 2021
Published by the National Vulnerability Database
Jun 22, 2021
Published to the GitHub Advisory Database
Jun 23, 2021
Last updated
Jan 29, 2023
Impact
All versions of Pterodactyl Wings preior to
1.4.4
are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding.Patches
Users should upgrade to
1.4.4
.Workarounds
There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.
For more information
If you have any questions or comments about this advisory:
dane ät pterodactyl dot io
References