CVE-2023-33245
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
30/05/2023
Last modified:
10/01/2025
Description
Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:minecraft:minecraft:*:*:*:*:java:*:*:* | 1.19 (including) | |
| cpe:2.3:a:minecraft:minecraft:1.20:pre-release1:*:*:java:*:*:* | ||
| cpe:2.3:a:minecraft:minecraft:1.20:pre-release2:*:*:java:*:*:* | ||
| cpe:2.3:a:minecraft:minecraft:1.20:pre-release3:*:*:java:*:*:* | ||
| cpe:2.3:a:minecraft:minecraft:1.20:pre-release4:*:*:java:*:*:* | ||
| cpe:2.3:a:minecraft:minecraft:1.20:pre-release5:*:*:java:*:*:* | ||
| cpe:2.3:a:minecraft:minecraft:1.20:pre-release6:*:*:java:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://help.minecraft.net/hc/en-us/articles/16165590199181
- https://vuln.ryotak.net/advisories/67
- https://www.minecraft.net/ja-jp/article/minecraft-1-20-pre-release-7
- https://help.minecraft.net/hc/en-us/articles/16165590199181
- https://vuln.ryotak.net/advisories/67
- https://www.minecraft.net/ja-jp/article/minecraft-1-20-pre-release-7



