PT-2024-33168 · Unknown · Command Block Ide

Apple502J

·

Published

2024-10-21

·

Updated

2024-10-23

·

CVE-2024-48645

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Command Block IDE versions up to and including 0.4.9
Description The issue is related to a missing authorization that allows any user to modify function files used by the game when the mod is installed on a dedicated server. This is due to an authorization flaw.
Recommendations For Command Block IDE versions up to and including 0.4.9, consider restricting access to the function files to prevent unauthorized modifications until a patch is available.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48645

Affected Products

Command Block Ide