Denial of Service in PocketMine-MP due to Improper NBT Data Validation
CVE-2022-51012
7.1HIGH
What is CVE-2022-51012?
PocketMine-MP versions prior to 4.2.9 are vulnerable to denial of service attacks due to inadequate validation of NBT data types during the deserialization of inventory transaction packets. Attackers can exploit this vulnerability by sending specially crafted inventory transactions with improperly formatted NBT tags, leading to server crashes and unavailability. It is crucial for users of affected versions to update to 4.2.9 or later to mitigate the risks associated with this vulnerability.
Affected Version(s)
PocketMine-MP 0 < 4.2.9
PocketMine-MP 4.2.9
