Retour à la veille

CVE-2020-37277

Publié : 6 septembre 2026
Modifié : 6 septembre 2026
Lien officiel NVD
Score CVSS
6.5
MEDIUM

Description détaillée

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Références et Patchs