PocketMine-MP 在 3.15.4 之前的版本中,其 InventoryTransaction 组件的 findResultItem() 方法存在拒绝服务(DoS)漏洞。恶意客户端可以发送精心构造的 InventoryTransaction 数据包,其中包含多个相互冲突的路径,从而导致指数级增长的处理复杂度,最终导致服务器冻结。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | < 3.15.4 |
affected |
3.15.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | 0 ~ 3.15.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51009 | 7.5 HIGH | PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry |
| CVE-2021-48007 | 6.5 MEDIUM | PocketMine-MP before 3.18.1 Denial of Service via MovePlayerPacket |
| CVE-2022-51008 | 5.3 MEDIUM | PocketMine-MP before 4.12.3 Denial of Service via Unauthenticated Sessions |
| CVE-2021-48006 | 3.3 LOW | PocketMine-MP before 4.0.3 Operator Privilege Escalation via Case Sensitivity |
No comments yet