2023-05-30 06:00:27 +00:00
{
"id" : "CVE-2023-33245" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2023-05-30T05:15:12.120" ,
2023-06-05 20:01:50 +00:00
"lastModified" : "2023-06-05T18:34:45.270" ,
"vulnStatus" : "Analyzed" ,
2023-05-30 06:00:27 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink."
}
] ,
2023-06-05 20:01:50 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-59"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:minecraft:minecraft:*:*:*:*:java:*:*:*" ,
"versionEndIncluding" : "1.19" ,
"matchCriteriaId" : "A571DE7F-0DF8-4DEA-8F0C-FF778268BBEB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:minecraft:minecraft:1.20:pre-release1:*:*:java:*:*:*" ,
"matchCriteriaId" : "ABE61DF5-1D28-4A9E-B8A3-E2527ED1C9D2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:minecraft:minecraft:1.20:pre-release2:*:*:java:*:*:*" ,
"matchCriteriaId" : "0D581D3D-68E5-4913-9096-50F6FED273CA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:minecraft:minecraft:1.20:pre-release3:*:*:java:*:*:*" ,
"matchCriteriaId" : "B62CDE85-6C18-4ACB-B638-CF27F5124F93"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:minecraft:minecraft:1.20:pre-release4:*:*:java:*:*:*" ,
"matchCriteriaId" : "E6FE2F58-B0BE-4B95-B0B9-47DCD940918A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:minecraft:minecraft:1.20:pre-release5:*:*:java:*:*:*" ,
"matchCriteriaId" : "8CE3DC1D-3E8F-4988-828A-107B90B56F7B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:minecraft:minecraft:1.20:pre-release6:*:*:java:*:*:*" ,
"matchCriteriaId" : "84124E34-2471-4866-AACA-46EAD5683673"
}
]
}
]
}
] ,
2023-05-30 06:00:27 +00:00
"references" : [
{
"url" : "https://help.minecraft.net/hc/en-us/articles/16165590199181" ,
2023-06-05 20:01:50 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
2023-05-30 06:00:27 +00:00
} ,
{
"url" : "https://vuln.ryotak.net/advisories/67" ,
2023-06-05 20:01:50 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
2023-05-30 06:00:27 +00:00
} ,
{
"url" : "https://www.minecraft.net/ja-jp/article/minecraft-1-20-pre-release-7" ,
2023-06-05 20:01:50 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Release Notes"
]
2023-05-30 06:00:27 +00:00
}
]
}