CVE-2022-39221
Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone via HTTP request.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone via HTTP request. Version 0.2.0 with patches are released to both platforms (Fabric and Quilt, Forge). As a workaround, the McWebserver mod can be disabled by removing the file from the `mods` directory.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- mcwebserver minecraft mod for fabric and quilt project/mcwebserver minecraft mod for fabric and quilt · mcwebserver minecraft mod for forge project/mcwebserver minecraft mod for forge
- Source
- security-advisories@github.com
References
- https://github.com/J-onasJones/McWebserver/pull/1Patch, Third Party Advisory
- https://github.com/J-onasJones/McWebserver/security/advisories/GHSA-gcvq-42cx-r46qThird Party Advisory
- https://github.com/J-onasJones/McWebserver/pull/1Patch, Third Party Advisory
- https://github.com/J-onasJones/McWebserver/security/advisories/GHSA-gcvq-42cx-r46qThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.