CVE-2022-51010
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid range to trigger an uncaught exception that crashes the server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | 0 < 4.4.2 | affected |
| pmmp | PocketMine-MP | 4.4.2 | unaffected |
Weaknesses
- CWE-20: Improper Input Validation
References
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-fqx3-r75h-vc89
- https://github.com/pmmp/PocketMine-MP/commit/5fd685e07d61ef670584ed11a52fd5f4b99a81a7
- https://www.vulncheck.com/advisories/pocketmine-mp-before-4.4.2-server-crash-via-item-id
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.