Vulnerability Description
SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn642's Config Lib between 1.0.4 and 1.0.8 are affected by a vulnerability and can be exploited on both servers and clients. Using SuperMartijn642's Config Lib, servers will send a packet to clients with the server's config values. In order to read `enum` values from the packet data, `ObjectInputStream#readObject` is used. `ObjectInputStream#readObject` will instantiate a class based on the input data. Since, the packet data is not validated before `ObjectInputStream#readObject` is called, an attacker can instantiate any class by sending a malicious packet. If a suitable class is found, the vulnerability can lead to a number of exploits, including remote code execution. Although the vulnerable packet is typically only send from server to client, it can theoretically also be send from client to server. This means both clients and servers running SuperMartijn642's Config Lib between 1.0.4 and 1.0.8 are vulnerable. The vulnerability has been patched in SuperMartijn642's Config lib 1.0.9. Both, players and server owners, should update to 1.0.9 or higher.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Config Lib Project | Config Lib | >= 1.0.4, < 1.0.9 |
Related Weaknesses (CWE)
References
- https://github.com/SuperMartijn642/SuperMartijn642sConfigLib/security/advisoriesThird Party Advisory
- https://github.com/SuperMartijn642/SuperMartijn642sConfigLib/security/advisoriesThird Party Advisory
FAQ
What is CVE-2021-37632?
CVE-2021-37632 is a vulnerability with a CVSS score of 8.1 (HIGH). SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn642's Config Lib between 1.0.4 and 1.0.8 are affected by a vulnerability and can ...
How severe is CVE-2021-37632?
CVE-2021-37632 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37632?
Check the references section above for vendor advisories and patch information. Affected products include: Config Lib Project Config Lib.