سایبرنامه
medium

CVE-2020-37277

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.

امتیاز CVSS

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

تحلیلِ بردارِ CVSS

CWE
CWE-400
تاریخ انتشار
۱۵ شهریور ۱۴۰۵

منابع