Mojira Archive
MC-80483

Creative mode is completely broken from a security standpoint

Creative mode is completely broken and results in many exploits both past, present, and future. In particular it advocates the sending of client->server NBT (cause of DDoS style crashes), which is completely unsanitized and leads to bugs where players set privileged NBT only the server should be allowed to. Rather than address every edge case, creative mode should be reworked to only the slot ID of the item to be selected to be sent over the wire. There should be no client->server NBT involved.

Unresolved

[Mod] md_5

2015-05-22, 08:33 AM

2024-11-21, 02:05 PM

5

8

Confirmed

Important

Platform

Networking

Minecraft 1.8.4 - 1.19.3Minecraft 1.8.4, 1.15.2, 20w07a, 20w17a, 1.16.2, 1.19.3

-