在 4.2.9 版本之前的 PocketMine-MP 中,在反序列化来自客户端的库存事务数据包时,未能正确验证 NBT 数据类型。攻击者可以发送带有格式错误的 NBT 标签的库存事务,以触发服务器崩溃,从而导致拒绝服务(DoS)攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | < 4.2.9 |
affected |
4.2.9 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | 0 ~ 4.2.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51017 | 7.5 HIGH | PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data |
| CVE-2022-51013 | 6.5 MEDIUM | PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata |
| CVE-2022-51010 | 6.5 MEDIUM | PocketMine-MP before 4.4.2 Server Crash via Item ID |
| CVE-2022-51014 | 6.5 MEDIUM | PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding |
| CVE-2022-51018 | 6.5 MEDIUM | PocketMine-MP before 3.26.5 Input Validation via Book Pages |
| CVE-2022-51015 | 6.5 MEDIUM | PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket |
| CVE-2022-51016 | 6.1 MEDIUM | PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay |
| CVE-2022-51011 | 4.3 MEDIUM | PocketMine-MP before 4.2.10 Denial of Service via Chat Messages |
No comments yet