Lucene search

K
cve[email protected]CVE-2022-39221
HistorySep 21, 2022 - 12:15 a.m.

CVE-2022-39221

2022-09-2100:15:10
CWE-22
web.nvd.nist.gov
23
4
cve
2022
39221
mcwebserver
path traversal
minecraft
fabric
quilt
forge
http server
security vulnerability

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.7%

McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone via HTTP request. Version 0.2.0 with patches are released to both platforms (Fabric and Quilt, Forge). As a workaround, the McWebserver mod can be disabled by removing the file from the mods directory.

Affected configurations

Vulners
NVD
Node
j-onasjonesmcwebserverRange<0.2.0

CNA Affected

[
  {
    "product": "McWebserver",
    "vendor": "J-onasJones",
    "versions": [
      {
        "status": "affected",
        "version": "< 0.2.0"
      }
    ]
  }
]

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.7%

Related for CVE-2022-39221