Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

URGENT PATCH: Fixed critical security issue in C2S_UpdateItemStack packet #50

Open
wants to merge 1 commit into
base: 1.20-architectury
Choose a base branch
from

Conversation

JohnBorg123490
Copy link

@JohnBorg123490 JohnBorg123490 commented Jun 17, 2024

I'm running a modded Minecraft server network, and we've found a serious issue with a furnish packet that's actively being exploited by griefers. This caused a lot of damage to one of our servers - and after investigating other servers have been affected too by this same issue.

We've put together a patch that fixes the exploit - this should be pushed and merged to curseforge to prevent further damage to other servers.

@Wouink

@matteo335
Copy link

Hi,
And thank you for this patch.
I work for a few servers myself and would be interested in learning more about how the exploit works, if you don't mind explaining.

@JohnBorg123490

@Wouink
Copy link
Owner

Wouink commented Aug 31, 2024

Hi all,
Thanks for reporting that issue and sorry for reacting late. Furnish development is not my main activity.
I just fixed this exploit while updating the mod for 1.21.
Thanks for your PR @JohnBorg123490, i'll try to merge it with the 1.20 branch if i find some time for that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants