CVE-2024-43395 Information
Aug 17, 2024
cve
Description
CraftOS-PC 2 is a rewrite of the desktop port of CraftOS from the popular Minecraft mod ComputerCraft using C++ and a modified version of PUC Lua as well as SDL for drawing. Prior to version 2.8.3 users of CraftOS-PC 2 on Windows can escape the computer folder and access files anywhere without permission or notice by obfuscating ..s to bypass the internal check preventing parent directory traversal. Version 2.8.3 contains a patch for this issue.
Reference
https://github.com/MCJack123/craftos2/security/advisories/GHSA-hr3w-wc83-6923 https://github.com/MCJack123/craftos2/commit/f7a88b905560df4366fb69f09b70f05984e05ad3
Share on: