CVE-2022-24300

Description

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.714

Associated Vulnerability

VulnerabilityOS Platform
minetest security update(DSA-5075-1) minetest_5.3.0+repack-2.1+deb11u1_amd64.debLinux
minetest security update(DSA-5075-1) minetest_0.4.17.1+repack-1+deb10u1_amd64.debLinux
minetest security update(DSA-5075-1) minetest_0.4.17.1+repack-1+deb10u1_i386.debLinux
minetest security update(DSA-5075-1) Debian_minetest_0.4.17.1+repack-1+deb10u1_amd64.debLinux
minetest security update(DSA-5075-1) minetest_5.3.0+repack-2.1+deb11u1_i386.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234