PT-2023-25866 · Google+3 · Gcp+3

Jlleitschuh

·

Published

2023-07-07

·

Updated

2023-07-18

·

CVE-2023-37262

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CC: Tweaked versions prior to 1.20.1-1.106.0 CC: Tweaked versions prior to 1.19.4-1.106.0 CC: Tweaked versions prior to 1.19.2-1.101.3 CC: Tweaked versions prior to 1.18.2-1.101.3 CC: Tweaked versions prior to 1.16.5-1.101.3
Description The issue affects CC: Tweaked, a mod for Minecraft, allowing any player to gain access to sensitive information exposed via metadata services API endpoints on cloud hosting providers like AWS, GCP, and Azure. This could potentially allow them to pivot or privilege escalate into the hosting provider.
Recommendations For versions prior to 1.20.1-1.106.0, update to version 1.20.1-1.106.0 or later. For versions prior to 1.19.4-1.106.0, update to version 1.19.4-1.106.0 or later. For versions prior to 1.19.2-1.101.3, update to version 1.19.2-1.101.3 or later. For versions prior to 1.18.2-1.101.3, update to version 1.18.2-1.101.3 or later. For versions prior to 1.16.5-1.101.3, update to version 1.16.5-1.101.3 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-37262
GHSA-7P4W-MV69-2WM2
GHSA-VVFJ-XH7C-J2CM

Affected Products

Aws
Azure
Gcp
Minecraft