CVE-2021-39177
30.08.2021, 23:15
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can connect to the server to forge a LoginPacket with manipulated JWT token allowing impersonation as any user. Version 1.4.2-SNAPSHOT contains a patch for the issue. There are no known workarounds aside from upgrading.Enginsight
Vendor | Product | Version |
---|---|---|
geysermc | geyser | 𝑥 < 1.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References