CVE-2024-58381
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
Weakness
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
References
- https://github.com/pmmp/PocketMine-MP/commit/6872661fd03649cc7a8762c41c16e9ee5a4de1c9
- https://github.com/pmmp/PocketMine-MP/commit/b96a209f9e8b76b899a0d0918493cd87eb3c02a7
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-h6j3-j35f-v2x7
- https://www.vulncheck.com/advisories/pocketmine-mp-before-5.11.1-denial-of-service-via-loginpacket
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.