漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL
Vulnerability Description
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player head texture data. By supplying a crafted Base64-encoded skin texture URL via the /give command, an attacker can cause the Minecraft server to issue arbitrary HTTP GET requests to attacker-controlled or internal endpoints. This occurs server-side, without proper URL validation, and can be triggered by a Bedrock client. This vulnerability is fixed in 2.9.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Geyser 代码问题漏洞
Vulnerability Description
Geyser是GeyserMC开源的一个跨平台游戏版本桥接代理工具。 Geyser 2.9.3之前版本存在代码问题漏洞,该漏洞源于处理基岩玩家头部纹理数据时存在服务端请求伪造,可能导致攻击者通过/give命令提供特制的Base64编码皮肤纹理URL,使Minecraft服务器向攻击者控制的或内部端点发出任意HTTP GET请求。
CVSS Information
N/A
Vulnerability Type
N/A