CVE-2021-33790
Last modified
CVE-2021-33790 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the classpath with any data. EPSS estimates a 2.84% chance of exploitation in the next 30 days.
Description
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the classpath with any data. A class usable for exploitation might or might not be present, depending on what Minecraft modifications are installed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Techreborn | Reborncore | <= 3.13.8 |
| Techreborn | Reborncore | >= 3.19.0, < 3.19.5 |
| Techreborn | Reborncore | >= 4.2.0, < 4.2.10 |
| Techreborn | Reborncore | >= 4.7.0, < 4.7.3 |
References
- https://github.com/TechReborn/RebornCore/security/advisories/GHSA-r7pg-4xrf-7mrmThird Party Advisory
- https://vuln.ryotak.me/advisories/45Third Party Advisory
- https://www.curseforge.com/minecraft/mc-mods/reborncoreProduct, Third Party Advisory
- https://github.com/TechReborn/RebornCore/security/advisories/GHSA-r7pg-4xrf-7mrmThird Party Advisory
- https://vuln.ryotak.me/advisories/45Third Party Advisory
- https://www.curseforge.com/minecraft/mc-mods/reborncoreProduct, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33790?
How severe is CVE-2021-33790?
How do I fix CVE-2021-33790?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33782Windows Authenticode Spoofing Vulnerability5.5
- CVE-2021-33783Windows SMB Information Disclosure Vulnerability6.5
- CVE-2021-33784Windows Cloud Files Mini Filter Driver Elevation of Privileg…7.8
- CVE-2021-33785Windows AF_UNIX Socket Provider Denial of Service Vulnerabil…7.5
- CVE-2021-33786Windows LSA Security Feature Bypass Vulnerability8.1
- CVE-2021-33788Windows LSA Denial of Service Vulnerability7.5
- CVE-2021-33791Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2021-33792Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have…7.8
- CVE-2021-33793Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have…9.8
- CVE-2021-33794Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allo…9.1
- CVE-2021-33795Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 prod…5.5
- CVE-2021-33796In MuJS before version 1.1.2, a use-after-free flaw in the r…7.5
Are you affected by CVE-2021-33790?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
