Multiverse-Core

Multiverse-Core

6M Downloads

Multiverse exploit FIXED

ConstructorLeo opened this issue ยท 12 comments

commented

Information

Details

I was able to reproduce my issue on a freshly setup and up-to-date server with the latest version of Multiverse plugins with no other plugins and with no kinds of other server or client mods.

Description
Upon typing a Multiverse command a player can crash a server.

Steps to reproduce
Simply type /mv __REDACTED__ into chat.

Expected behavior
Does not crash the server.

Screenshots
SCREENSHOT REDACTED

commented

I am sorry, but was a fix-build pushed? I see no commits relating to this.

commented
commented

Thanks Ben! Updating our MV right now.

commented

I can confirm it too.
Adding a permission in plugin.yml for all commands has fixed the issue for me.

Crash is also possible in older versions. it works with all versions without permissions in plugin,yml

commented

I can confirm this a bug. Someone did same thing to crash my server less than an hour ago on server version 1.13.2. Then went to my 1.16 server and did same thing. This exploit appears to exist in all version of multiverse going years back.

commented

Update to latest dev builds, we will push a release asap

https://ci.onarandombox.com/job/Multiverse-Core/

commented

I created a plugin for those unable to or unwilling to install the latest version of Multiverse to prevent people from getting their servers crashed.
https://www.spigotmc.org/resources/multiverse-crashfix.96301/

commented

For those using older multiverse builds and can't update for whatever reason: https://www.spigotmc.org/resources/multiverse-patches.96390/

commented

Multiverse-Core 4.3.1 this was fixed version?

commented

Yes

commented

@wotnurwasfrage read the issue comments above.

commented

For those that see this issue, we have fixed it so JUST UPDATE: https://www.spigotmc.org/resources/multiverse-core.390/update?update=424085

We have also noted that some people are unable to update for whatever reason. Then just grab the patch: https://www.spigotmc.org/resources/multiverse-patches.96390/ (Tho we still recommend you ultimately update mv)