PT-2023-25866 · Google+3 · Gcp+3

Jlleitschuh

·

Publicado

2023-07-07

·

Atualizado

2023-07-18

·

CVE-2023-37262

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CC: Tweaked versions prior to 1.20.1-1.106.0 CC: Tweaked versions prior to 1.19.4-1.106.0 CC: Tweaked versions prior to 1.19.2-1.101.3 CC: Tweaked versions prior to 1.18.2-1.101.3 CC: Tweaked versions prior to 1.16.5-1.101.3
Description The issue affects CC: Tweaked, a mod for Minecraft, allowing any player to gain access to sensitive information exposed via metadata services API endpoints on cloud hosting providers like AWS, GCP, and Azure. This could potentially allow them to pivot or privilege escalate into the hosting provider.
Recommendations For versions prior to 1.20.1-1.106.0, update to version 1.20.1-1.106.0 or later. For versions prior to 1.19.4-1.106.0, update to version 1.19.4-1.106.0 or later. For versions prior to 1.19.2-1.101.3, update to version 1.19.2-1.101.3 or later. For versions prior to 1.18.2-1.101.3, update to version 1.18.2-1.101.3 or later. For versions prior to 1.16.5-1.101.3, update to version 1.16.5-1.101.3 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37262
GHSA-7P4W-MV69-2WM2
GHSA-VVFJ-XH7C-J2CM

Produtos afetados

Aws
Azure
Gcp
Minecraft