CVE-2023-33245

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
30/05/2023
Last modified:
10/01/2025

Description

Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:minecraft:minecraft:*:*:*:*:java:*:*:* 1.19 (including)
cpe:2.3:a:minecraft:minecraft:1.20:pre-release1:*:*:java:*:*:*
cpe:2.3:a:minecraft:minecraft:1.20:pre-release2:*:*:java:*:*:*
cpe:2.3:a:minecraft:minecraft:1.20:pre-release3:*:*:java:*:*:*
cpe:2.3:a:minecraft:minecraft:1.20:pre-release4:*:*:java:*:*:*
cpe:2.3:a:minecraft:minecraft:1.20:pre-release5:*:*:java:*:*:*
cpe:2.3:a:minecraft:minecraft:1.20:pre-release6:*:*:java:*:*:*