Denial of Service Vulnerability in PocketMine-MP by PocketMine Team
CVE-2022-51009
8.7HIGH
What is CVE-2022-51009?
PocketMine-MP versions prior to 4.7.2 are susceptible to a Denial of Service vulnerability due to improper handling of exceptions from the adhocore/json-comment library. Attackers can exploit this flaw by sending malformed login or skin packets containing invalid geometry JSON. The resulting unhandled RuntimeException can lead to server crashes, interrupting service and impacting users.
Affected Version(s)
PocketMine-MP 0 < 4.7.2
PocketMine-MP 4.7.2
