PocketMine-MP 在 4.2.3 之前的版本未能验证来自客户端的工具和护甲物品 NBT 数据中的损坏(耐久度)元数据值。攻击者可以在物品堆栈(ItemStack)的 NBT 中发送负数或超出范围的损坏值,从而在 Durable 类中触发未处理的异常,导致服务器崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | < 4.2.3 |
affected |
4.2.3 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | 0 ~ 4.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51017 | 7.5 HIGH | PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data |
| CVE-2022-51010 | 6.5 MEDIUM | PocketMine-MP before 4.4.2 Server Crash via Item ID |
| CVE-2022-51014 | 6.5 MEDIUM | PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding |
| CVE-2022-51012 | 6.5 MEDIUM | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization |
| CVE-2022-51018 | 6.5 MEDIUM | PocketMine-MP before 3.26.5 Input Validation via Book Pages |
| CVE-2022-51015 | 6.5 MEDIUM | PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket |
| CVE-2022-51016 | 6.1 MEDIUM | PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay |
| CVE-2022-51011 | 4.3 MEDIUM | PocketMine-MP before 4.2.10 Denial of Service via Chat Messages |
No comments yet