Описание
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | pending | 5.15.2+dfsg-2build1 |
| esm-apps/resolute | released | 5.10.0+dfsg-5+deb13u1build0.26.04.1 |
| jammy | DNE | |
| noble | DNE | |
| questing | released | 5.10.0+dfsg-5+deb13u1build0.25.10.1 |
| resolute | released | 5.10.0+dfsg-5+deb13u1build0.26.04.1 |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
8.1 High
CVSS3
Связанные уязвимости
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecu ...
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.
EPSS
8.1 High
CVSS3