{"id":"GHSA-3qpm-h9ch-px3c","summary":"Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library","details":"### Summary\nThe version used of Log4j, the library used for logging by PowerNukkit, is subject to a remote code execution vulnerability via the ldap JNDI parser.\nIt's well detailed at [CVE-2021-44228](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q) and  CVE-2021-45105(https://github.com/advisories/GHSA-p6xc-xr62-6r2g).\n\n### Impact\nMalicious client code could be used to send messages and cause remote code execution on the server.\n\n### Patches\nPowerNukkit `1.5.2.1` is a patch-release that only updates the Log4j version to `2.17.0` and should be used instead of `1.5.2.0`.\nAll versions prior to `1.5.2.1` are affected and are not patched.\n\n### Workarounds\nIf you can't upgrade, you can use the `-Dlog4j2.formatMsgNoLookups=true` startup argument as remediation, as this prevents the vulnerability from happening.\n\n### References\nhttps://github.com/advisories/GHSA-jfh8-c2jp-5v3q\nhttps://github.com/advisories/GHSA-p6xc-xr62-6r2g\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the PowerNukkit repository](https://github.com/PowerNukkit/PowerNukkit/issues)\n","modified":"2024-12-04T05:40:03.827618Z","published":"2022-01-06T18:31:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-01-04T22:06:05Z","nvd_published_at":null,"cwe_ids":["CWE-20","CWE-400","CWE-502"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/PowerNukkit/PowerNukkit/security/advisories/GHSA-3qpm-h9ch-px3c"},{"type":"PACKAGE","url":"https://github.com/PowerNukkit/PowerNukkit"}],"affected":[{"package":{"name":"org.powernukkit:powernukkit","ecosystem":"Maven","purl":"pkg:maven/org.powernukkit/powernukkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.2.1"}]}],"versions":["1.1.1.0-PN","1.1.1.1-PN","1.2.0.0-PN","1.2.0.2-PN","1.2.1.0-PN","1.3.0.1-PN","1.3.1.1-PN","1.3.1.2-PN","1.3.1.3-PN","1.3.1.4-PN","1.3.1.5-PN","1.3.2.0-PN-ALPHA.2","1.3.2.0-PN-ALPHA.3","1.4.0.0-PN","1.4.0.0-PN-ALPHA.1","1.4.0.0-PN-ALPHA.2","1.5.0.0-PN","1.5.1.0-PN","1.5.2.0-PN"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.5.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-3qpm-h9ch-px3c/GHSA-3qpm-h9ch-px3c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}