Описание
RegionProtect is a plugin that allows users to manage certain events in certain regions of the world. Versions prior to 1.1.0 contain a YAML injection vulnerability that can cause an instant server crash if the passed arguments are not matched. Version 1.1.0 contains a patch for this issue. As a workaround, restrict operator permissions to untrusted people and avoid entering arguments likely to cause a crash.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.0 (исключая)
cpe:2.3:a:regionprotect_project:regionprotect:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00299
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-88
CWE-88
EPSS
Процентиль: 53%
0.00299
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-88
CWE-88