PT-2021-22435 · Geyser · Geyser

Camotoy

+3

·

Published

2021-08-30

·

Updated

2021-09-10

·

CVE-2021-39177

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Geyser versions prior to 1.4.2-SNAPSHOT
Description The issue allows anyone that can connect to the server to forge a LoginPacket with a manipulated JWT token, enabling impersonation as any user. This affects users who have saved their credentials in the configuration. However, online mode is not affected if credentials are not saved, as users are still required to log in separately. The estimated number of potentially affected devices is not provided.
Recommendations To resolve the issue, upgrade to Geyser version 1.4.2-SNAPSHOT or later. As a temporary workaround, consider using online mode and avoid saving credentials in the Geyser configuration. Additionally, using an extra authentication method on the Java server can help minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39177
GHSA-H77F-XXX7-4858

Affected Products

Geyser