Vulnerability Description
Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Minecraft | Minecraft | <= 1.19 |
Related Weaknesses (CWE)
References
- https://help.minecraft.net/hc/en-us/articles/16165590199181Vendor Advisory
- https://vuln.ryotak.net/advisories/67Third Party Advisory
- https://www.minecraft.net/ja-jp/article/minecraft-1-20-pre-release-7Release Notes
- https://help.minecraft.net/hc/en-us/articles/16165590199181Vendor Advisory
- https://vuln.ryotak.net/advisories/67Third Party Advisory
- https://www.minecraft.net/ja-jp/article/minecraft-1-20-pre-release-7Release Notes
FAQ
What is CVE-2023-33245?
CVE-2023-33245 is a vulnerability with a CVSS score of 8.8 (HIGH). Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink.
How severe is CVE-2023-33245?
CVE-2023-33245 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33245?
Check the references section above for vendor advisories and patch information. Affected products include: Minecraft Minecraft.