ZeroHour

CVE-2022-51013

moderate

Input Validation Flaw in PocketMine-MP Before 4.2.3 Lets Players Crash Servers

CVSS 4.0
7.1 high
EPSS
<1%p42
Published
()
Modified
AI analysis

PocketMine-MP versions before 4.2.3, an open-source dedicated server for Minecraft: Bedrock Edition, fail to validate damage metadata values in the NBT data clients send for tool and armor items (CWE-20). A connected player can send crafted itemstack NBT containing negative or out-of-range damage values, triggering unhandled exceptions in the Durable class that crash the server. The impact is denial of service: per the CVSS 4.0 vector, availability is heavily affected while confidentiality and integrity are unaffected, and only low privileges (a connected player session) are required. Any operator running an affected version is exposed, with public servers that allow item exchange or creative-style gameplay most likely to be targeted. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.5% probability of exploitation within 30 days.

What to do: Upgrade PocketMine-MP to version 4.2.3 or later. Operators who cannot upgrade immediately should check their current server version, be aware that any connected player can trigger a crash, and consider limiting access to trusted players or monitoring for server restarts. Given the low EPSS score and absence of a public PoC, urgent action beyond patching is not required.

Affected
PocketMine-MP Project PocketMine-MPall versions before 4.2.3
Estimated exposure
moderatethousands of community-run Minecraft Bedrock servers (exact active-install count unknown) — PocketMine-MP is one of the most widely used open-source alternatives to official Bedrock Dedicated Server software, and public Minecraft Bedrock server listings have historically catalogued thousands of PocketMine-powered servers, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemstack NBT to trigger unhandled exceptions in the Durable class, causing server crashes.

Weakness
CWE-20
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.