GHSA-46c5-pfj8-fv65
Improperly checked metadata on tools/armour itemstacks received from the client
Quick fix
GHSA-46c5-pfj8-fv65 — pocketmine/pocketmine-mp: upgrade to the fixed version with the command below.
composer require pocketmine/pocketmine-mp:^4.2.4Details
### Impact Due to a workaround applied in 1.13, an attacker may send a negative damage/meta value in a tool or armour item's NBT, which `TypeConverter` then blindly uses as if it was valid without being checked.
When this invalid metadata value reaches `Durable->setDamage()`, an exception is thrown because the metadata is not within the expected range for damage values.
This can be reproduced with either a too-large damage value, or a negative one.
### Patches c8e1cfcbee4945fd4b63d2a7e96025c59744d4f1
### Workarounds In theory this can be checked by plugins using a custom `TypeConverter`, but this is likely to be very cumbersome.
### For more information * Email us at [team@pmmp.io](mailto:team@pmmp.io)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.2.4composer require pocketmine/pocketmine-mp:^4.2.4