CC: Tweaked SSRF to Cloud Services Metadata Services not Blocked by Default
CVE-2023-37262

9.6CRITICAL

Key Information:

Vendor

Cc-tweaked

Vendor
CVE Published:
7 July 2023

What is CVE-2023-37262?

CC: Tweaked, a Minecraft mod by MightyPirates, had a vulnerability that allowed players to access sensitive metadata from cloud service providers like AWS, GCP, and Azure due to the cc-tweaked plugin not adequately restricting access to metadata services. This oversight potentially allowed unauthorized users to gain critical information, posing risks such as privilege escalation and unauthorized access to the underlying cloud infrastructure. Users are urged to update to the latest fixed versions to secure their servers.

Affected Version(s)

CC-Tweaked < 1.16.5-1.101.3 < 1.16.5-1.101.3

CC-Tweaked >= 1.17.0, < 1.18.2-1.101.3 < 1.17.0, 1.18.2-1.101.3

CC-Tweaked >= 1.19.0, < 1.19.2-1.101.3 < 1.19.0, 1.19.2-1.101.3

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.