CVE-2020-37277
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | 0 < 3.15.4 | affected |
| pmmp | PocketMine-MP | 3.15.4 | unaffected |
Weaknesses
- CWE-400: Uncontrolled Resource Consumption
References
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-8jq6-w5cg-wm45
- https://github.com/pmmp/PocketMine-MP/commit/c368ebb5e74632bc622534b37cd1447b97281e20
- https://www.vulncheck.com/advisories/pocketmine-mp-before-3.15.4-denial-of-service-via-inventorytransaction
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.