pterodactyl / panel

Pterodactyl® is a free, open-source game server management panel built with PHP, React, and Go. Designed with security in mind, Pterodactyl runs all game servers in isolated Docker containers while exposing a beautiful and intuitive UI to end users.
https://pterodactyl.io
Other
6.59k stars 1.65k forks source link

Users gets placed into other's account #5192

Open Krstf01 opened 3 weeks ago

Krstf01 commented 3 weeks ago

Current Behavior

Today every user got placed into one customer's account including me too (admin). This happened before while we tested this, and was not able to recreate this issue, it seems happening randomly. Is this some well known issue, or unknow? Also worth mentioning i have "stellar" theme installed.

Expected Behavior

The expected is to not put everyone into one user's account, obviously.

Steps to Reproduce

Install stellar theme Have multiple users registered Log in Close the page Open the panel again (it happens rarely, but if someone gets into one of the admin's account, thats a serious vulnerability i think)

Panel Version

1.11.7

Wings Version

1.11.13

Games and/or Eggs Affected

No response

Docker Image

No response

Error Logs

No response

Is there an existing issue for this?

MackenzieMolloy commented 3 weeks ago

Steps to Reproduce Install stellar theme

Are you able to reproduce this issue with no modifications made to Pterodactyl's source code?

If not, it's an issue either with your installation of the theme or the theme it's self and thus you should contact the theme author.

danny6167 commented 3 weeks ago

This is likely an issue with your modification, or some kind of proxy or other component specific to your setup that is misbehaving.

Nobody else has ever reported anything like this happening.

Mutex21 commented 2 weeks ago

Do you have any layer7 protection installed on your system? Also, are you behind proxy or Cloudflare?