Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7whh-79j3-7c55

Опубликовано: 28 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

InventoryGui allows item duplication in GUIs which use GuiStorageElement

Impact

Any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element.

Patches

InventoryGui 1.6.5 (included in latest 1.6.5-SNAPSHOT) by disabling GuiStorageElement when not running on 1.21.9 or later.

Workarounds

Not using the GuiStorageElement.

Пакеты

Наименование

de.themoep:inventorygui

maven
Затронутые версииВерсия исправления

< 1.6.5

1.6.5

EPSS

Процентиль: 13%
0.00043
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-837

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5.

EPSS

Процентиль: 13%
0.00043
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-837