Authentication Bypass Vulnerability in PocketMine-MP by PocketMine Team
CVE-2022-51016
5.3MEDIUM
What is CVE-2022-51016?
The PocketMine-MP server software for Minecraft, versions 3.x prior to 3.27.0, lacks proper encryption for the Minecraft Bedrock protocol, leading to the potential for an authentication bypass. Attackers can exploit this vulnerability by capturing a valid login token from a player's session. By tricking the player into connecting to a malicious server, the attacker can impersonate the victim and maintain unauthorized access to XBOX Live functionalities until the token expires. This vulnerability primarily impacts servers accessible over the internet without encryption or proxy protection. The issue has been resolved in version 4.0.0 and backported to 3.27.0.
