WorldGuard Report Security Vulnerability
LadyCailinBot opened this issue ยท 0 comments
WORLDGUARD-3079 - Reported by BeastsMC.BeastsMC
Worldguard provides the host key function to add additional security to Minecraft servers in the case of Mojang's authentication service being compromised. The key to this security is keeping the host keys secret. Unfortunately, when you use "worldguard report -p" to upload and diagnose an issue, all of your host keys are included in that report. Malicious users can find the keys by googling the username of a player with the host key. Even though the pastes are set to expire after 24h, google indexes the page and the index text is still viewable/cached.