PT-2022-16591 · Minetest+1 · Minetest+1

Rubenwardy

·

Published

2021-03-08

·

Updated

2023-08-08

·

CVE-2022-24300

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Minetest versions prior to 5.4.0
Description The issue allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, also known as ItemStack meta injection.
Recommendations For versions prior to 5.4.0, update to version 5.4.0 or later to resolve the issue.

Fix

Related Identifiers

ALT-PU-2021-1448
ALT-PU-2021-1604
ALT-PU-2022-2540
CVE-2022-24300
DSA-5075-1
GHSA-HWJ2-XF72-R4CF

Affected Products

Alt Linux
Minetest