CVE-2023-54390
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-1025: Comparison Using Wrong Factors
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-92jh-gwch-jq38
- https://github.com/pmmp/PocketMine-MP/commit/4f90e8dab1c9df331fad7d3d89823404e882668c
- https://www.vulncheck.com/advisories/pocketmine-mp-before-5.3.1-denial-of-service-via-loginpacket
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.