PocketMine-MP 3.x 版本(3.27.0 之前)未实现 Minecraft Bedrock 协议加密,导致服务器无法验证连接客户端是否持有与其登录令牌(login token)对应的私钥。攻击者若截获了另一名玩家会话中的有效登录信息(例如诱使玩家连接到攻击者控制的服务器),即可重放该登录请求,从而冒充受害者,并在使用该 JWT 令牌过期前(通常为期 2-3 天)通过 XBOX Live 身份验证。此问题影响的是可直接通过互联网访问、且未处于启用加密的代理之后的服务器。该漏洞已在 4.0.0 中修复,并
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51017 | 7.5 HIGH | PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data |
| CVE-2022-51013 | 6.5 MEDIUM | PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata |
| CVE-2022-51010 | 6.5 MEDIUM | PocketMine-MP before 4.4.2 Server Crash via Item ID |
| CVE-2022-51014 | 6.5 MEDIUM | PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding |
| CVE-2022-51012 | 6.5 MEDIUM | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization |
| CVE-2022-51018 | 6.5 MEDIUM | PocketMine-MP before 3.26.5 Input Validation via Book Pages |
| CVE-2022-51015 | 6.5 MEDIUM | PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket |
| CVE-2022-51011 | 4.3 MEDIUM | PocketMine-MP before 4.2.10 Denial of Service via Chat Messages |
No comments yet