{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2023-54396", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-09-05T21:00:50.888Z", "datePublished": "2026-09-09T13:31:54.170Z", "dateUpdated": "2026-10-08T15:21:09.045Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-08T15:21:09.045Z" }, "datePublic": "2023-01-06T00:00:00.000Z", "title": "PocketMine-MP before 4.8.1 Server Crash via Banner NBT", "descriptions": [ { "lang": "en", "value": "PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server." } ], "tags": [ "unsupported-when-assigned" ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Improper Validation of Array Index", "cweId": "CWE-129", "type": "CWE" } ] } ], "affected": [ { "vendor": "pmmp", "product": "PocketMine-MP", "defaultStatus": "unaffected", "versions": [ { "version": "0", "status": "affected", "versionType": "semver", "lessThan": "4.8.1" }, { "version": "4.8.1", "status": "unaffected", "versionType": "semver" } ], "packageURL": "pkg:composer/pocketmine/pocketmine-mp" } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 7.1, "baseSeverity": "HIGH" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM" } } ], "references": [ { "url": "https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-wqqv-jcfr-9f5g", "tags": [ "vendor-advisory" ], "name": "GitHub Security Advisory (GHSA-wqqv-jcfr-9f5g)" }, { "url": "https://github.com/pmmp/PocketMine-MP/commit/08b9495bce2d65a6d1d3eeb76e484499a00765eb", "tags": [ "patch" ], "name": "Patch Commit" }, { "name": "VulnCheck Advisory: PocketMine-MP before 4.8.1 Server Crash via Banner NBT", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/pocketmine-mp-before-4.8.1-server-crash-via-banner-nbt" } ], "x_generator": { "engine": "vulncheck-endgame" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-09T14:10:39.674626Z", "id": "CVE-2023-54396", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-09T14:10:48.619Z" } } ] } }