Hbm's Nuclear Tech Mod

Hbm's Nuclear Tech Mod

1M Downloads

[SYSTEM VULNERABILITY] possible serialization exploit notice (please read)

Shibva opened this issue · 1 comments

commented

Hello… Long time no see. I make the report as to bring awareness of another security issue that has been found as of recently regarding the "bleeding pipe" exploit.

While I am not 100% certain, there's a possibility that some code in this mod if it uses any sort of serialization that is used in Java8 and if so, is unsafe if used in a server environment

This security hole is similar to the ordeal with Log4j.

For more information regarding this, please refer to the link below:

https://github.com/dogboy21/serializationisbad

Again, this report is the bring awareness of a possible security issue, and if present to be hopefully patched. That's all.

Stay safe out there and take care 🙂

commented

NTM has no mention of ObjectInputStream in packets or otherwise.