CVE-2024-58381
Dashboard / Vulnerabilities / CVE-2024-58381
Summary: PocketMine-MP before 5.11.1 Denial of Service via LoginPacket
Details: PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58381.json, https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-h6j3-j35f-v2x7, https://nvd.nist.gov/vuln/detail/CVE-2024-58381, https://www.vulncheck.com/advisories/pocketmine-mp-before-5.11.1-denial-of-service-via-loginpacket, https://github.com/pmmp/PocketMine-MP/commit/6872661fd03649cc7a8762c41c16e9ee5a4de1c9, https://github.com/pmmp/PocketMine-MP/commit/b96a209f9e8b76b899a0d0918493cd87eb3c02a7
Affected packages
Package
Name:
Purl:
