GHSA-46c5-pfj8-fv65

    Dashboard / Vulnerabilities / GHSA-46c5-pfj8-fv65

    GHSA-46c5-pfj8-fv65

    Published: 18 Mar 2022Last Modified: 8 Sept 2026

    Summary: Improperly checked metadata on tools/armour itemstacks received from the client

    Details: ### Impact Due to a workaround applied in 1.13, an attacker may send a negative damage/meta value in a tool or armour item's NBT, which `TypeConverter` then blindly uses as if it was valid without being checked. When this invalid metadata value reaches `Durable->setDamage()`, an exception is thrown because the metadata is not within the expected range for damage values. This can be reproduced with either a too-large damage value, or a negative one. ### Patches c8e1cfcbee4945fd4b63d2a7e96025c59744d4f1 ### Workarounds In theory this can be checked by plugins using a custom `TypeConverter`, but this is likely to be very cumbersome. ### For more information * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: pocketmine/pocketmine-mp

    Purl: pkg:composer/pocketmine/pocketmine-mp

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.2.4

    Affected versions

    3.0.0
    3.0.1
    3.0.10
    3.0.11
    3.0.12
    3.0.2
    3.0.3
    3.0.4
    3.0.5
    3.0.6
    3.0.7
    3.0.8
    3.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-46c5-pfj8-fv65 | CVE-DB