PocketMine-MP 在 4.12.3 之前的版本未能对未认证会话进行限制,允许攻击者通过创建会话而不发送 LoginPacket 来耗尽玩家槽位。攻击者可以通过向服务器发送大量未认证连接来占用最大玩家槽位,从而阻止合法玩家加入服务器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | 4.0.0< 4.12.3 |
affected |
4.12.3 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | 4.0.0 ~ 4.12.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51009 | 7.5 HIGH | PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry |
| CVE-2021-48007 | 6.5 MEDIUM | PocketMine-MP before 3.18.1 Denial of Service via MovePlayerPacket |
| CVE-2020-37277 | 6.5 MEDIUM | PocketMine-MP before 3.15.4 Denial of Service via InventoryTransaction |
| CVE-2021-48006 | 3.3 LOW | PocketMine-MP before 4.0.3 Operator Privilege Escalation via Case Sensitivity |
No comments yet