Retour à la veille

CVE-2022-51009

Publié : 6 septembre 2026
Modifié : 6 septembre 2026
Lien officiel NVD
Score CVSS
7.5
HIGH

Description détaillée

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Références et Patchs