Denial of Service Vulnerability in PocketMine-MP by PocketMine Team
CVE-2020-37277
7.1HIGH
What is CVE-2020-37277?
PocketMine-MP versions prior to 3.15.4 are susceptible to a denial of service issue originating from the InventoryTransaction component. By sending specially crafted InventoryTransactionPackets that include multiple conflicting pathways, malicious clients can induce an exponential processing complexity on the server, effectively freezing it and impairing service availability. This vulnerability highlights the importance of timely updates to protect server integrity and performance.
Affected Version(s)
PocketMine-MP 0 < 3.15.4
PocketMine-MP 3.15.4
