The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the classpath with any data. A class usable for exploitation might or might not be present, depending on what Minecraft modifications are installed.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-05-31T04:00:33

Updated: 2021-05-31T04:00:33

Reserved: 2021-05-30T00:00:00


Link: CVE-2021-33790

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-31T04:15:08.153

Modified: 2021-06-11T19:38:06.083


Link: CVE-2021-33790

JSON object: View

cve-icon Redhat Information

No data.

CWE