PocketMine-MP 在 3.26.5 之前以及 4.0.x 在 4.0.5 之前,未对书籍页面文本长度、页面数量以及作者/标题长度进行限制。获取到可编辑书籍的玩家可创建超大的 NBT 数据(即“书籍炸弹”),导致带宽消耗过高以及服务器崩溃(在 PM3 中保存基于 region 的世界时会超过 1 MB 的区块大小限制;在 PM4 中则超过 32 KiB 的 TAG_String 限制)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-51017 | 7.5 HIGH | PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data |
| CVE-2022-51013 | 6.5 MEDIUM | PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata |
| CVE-2022-51010 | 6.5 MEDIUM | PocketMine-MP before 4.4.2 Server Crash via Item ID |
| CVE-2022-51014 | 6.5 MEDIUM | PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding |
| CVE-2022-51012 | 6.5 MEDIUM | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization |
| CVE-2022-51015 | 6.5 MEDIUM | PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket |
| CVE-2022-51016 | 6.1 MEDIUM | PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay |
| CVE-2022-51011 | 4.3 MEDIUM | PocketMine-MP before 4.2.10 Denial of Service via Chat Messages |
No comments yet