CVE-2023-37262

Source
https://cve.org/CVERecord?id=CVE-2023-37262
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37262.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-37262
Related
  • GHSA-7p4w-mv69-2wm2
  • GHSA-vvfj-xh7c-j2cm
Published
2023-07-07T20:17:42.919Z
Modified
2026-07-22T02:25:24.972240Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
CC: Tweaked SSRF to Cloud Services Metadata Services not Blocked by Default
Details

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to versions 1.20.1-1.106.0, 1.19.4-1.106.0, 1.19.2-1.101.3, 1.18.2-1.101.3, and 1.16.5-1.101.3, if the cc-tweaked plugin is running on a Minecraft server hosted on a popular cloud hosting providers, like AWS, GCP, and Azure, those metadata services API endpoints are not forbidden (aka "blacklisted") by default. As such, any player can gain access to sensitive information exposed via those metadata servers, potentially allowing them to pivot or privilege escalate into the hosting provider. Versions 1.20.1-1.106.0, 1.19.4-1.106.0, 1.19.2-1.101.3, 1.18.2-1.101.3, and 1.16.5-1.101.3 contain a fix for this issue.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37262.json"
}
References

Affected packages

Git / github.com/cc-tweaked/cc-tweaked

Affected ranges

Type
GIT
Repo
https://github.com/cc-tweaked/cc-tweaked
Events
Database specific
{
    "cpe": "cpe:2.3:a:tweaked:cc-tweaked:*:*:*:*:*:minecraft:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.16.5-1.101.3"
        },
        {
            "introduced": "1.17.1-1.98.1"
        },
        {
            "fixed": "1.18.2-1.101.3"
        },
        {
            "introduced": "1.19.1-1.100.9"
        },
        {
            "fixed": "1.19.2-1.101.3"
        },
        {
            "introduced": "1.19.3-1.102.0"
        },
        {
            "fixed": "1.19.4-1.106.0"
        },
        {
            "introduced": "1.20.1-1.105.0"
        },
        {
            "fixed": "1.20.1-1.106.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.79
1.80pr0
1.80pr1
v1.*
v1.12.2-1.81.0
v1.12.2-1.81.1
v1.12.2-1.82.0
v1.13.2-1.82.0
v1.13.2-1.82.3
v1.13.2-1.83.1
v1.14.3-1.83.1
v1.14.4-1.84.0
v1.14.4-1.84.1
v1.14.4-1.85.0
v1.14.4-1.85.1
v1.14.4-1.85.2
v1.14.4-1.86.0
v1.14.4-1.86.1
v1.14.4-1.86.2
v1.15.2-1.86.2
v1.15.2-1.87.0
v1.15.2-1.87.1
v1.15.2-1.88.0
v1.15.2-1.88.1
v1.15.2-1.89.0
v1.15.2-1.89.1
v1.16.1-1.90.0
v1.16.1-1.90.1
v1.16.1-1.90.2
v1.16.1-1.90.3
v1.16.2-1.91.0
v1.16.2-1.91.1
v1.16.3-1.92.0
v1.16.3-1.93.0
v1.16.3-1.93.1
v1.16.4-1.94.0
v1.16.4-1.95.0
v1.16.4-1.95.1
v1.16.4-1.95.2
v1.16.4-1.95.3
v1.16.4-1.96.0
v1.16.5-1.100.0
v1.16.5-1.100.1
v1.16.5-1.100.10
v1.16.5-1.100.2
v1.16.5-1.100.3
v1.16.5-1.100.4
v1.16.5-1.100.5
v1.16.5-1.100.6
v1.16.5-1.100.8
v1.16.5-1.100.9
v1.16.5-1.101.0
v1.16.5-1.101.2
v1.16.5-1.97.0
v1.16.5-1.98.0
v1.16.5-1.98.1
v1.16.5-1.98.2
v1.16.5-1.99.0
v1.16.5-1.99.1
v1.17.1-1.98.1
v1.17.1-1.98.2
v1.17.1-1.99.0
v1.18-1.99.0
v1.18.1-1.100.0
v1.18.1-1.100.1
v1.18.1-1.100.2
v1.18.1-1.99.1
v1.18.2-1.100.10
v1.18.2-1.100.3
v1.18.2-1.100.4
v1.18.2-1.100.5
v1.18.2-1.100.6
v1.18.2-1.100.8
v1.18.2-1.100.9
v1.18.2-1.101.0
v1.18.2-1.101.2
v1.19.1-1.100.9
v1.19.2-1.100.10
v1.19.2-1.101.0
v1.19.2-1.101.1
v1.19.2-1.101.2
v1.19.3-1.102.0
v1.19.3-1.102.1
v1.19.3-1.102.2
v1.19.3-1.103.0
v1.19.3-1.103.1
v1.19.4-1.104.0
v1.19.4-1.105.0
v1.20.1-1.105.0
v1.80pr1.1
v1.80pr1.10
v1.80pr1.11
v1.80pr1.12
v1.80pr1.13
v1.80pr1.14
v1.80pr1.2
v1.80pr1.3
v1.80pr1.4
v1.80pr1.5
v1.80pr1.6
v1.80pr1.7
v1.80pr1.8
v1.80pr1.9

Database specific

vanir_signatures_modified
"2026-07-22T02:25:24Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 154.0,
            "function_hash": "48939138621218488815824292088523064708"
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
        "id": "CVE-2023-37262-0154001c",
        "target": {
            "function": "testExtra",
            "file": "projects/core/src/test/java/dan200/computercraft/core/asm/MethodTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "180144484903901506208089478192765426312",
                "334659197182951094034655171936497399415",
                "232964441626505346179137990738064291507",
                "258529733809329783191523140932297187643"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
        "id": "CVE-2023-37262-06f206d2",
        "target": {
            "file": "projects/core/src/main/java/dan200/computercraft/core/asm/MethodSupplierImpl.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 765.0,
            "function_hash": "97912784879334948814938950326261085838"
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
        "id": "CVE-2023-37262-0d8590bd",
        "target": {
            "function": "forEachMethod",
            "file": "projects/core/src/main/java/dan200/computercraft/core/asm/MethodSupplierImpl.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 136.0,
            "function_hash": "301979240058404626912808031733699886564"
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/4bbde8c50c00bc572578ab2cff609b3443d10ddf",
        "id": "CVE-2023-37262-38efc77b",
        "target": {
            "function": "matches",
            "file": "projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "125240597833634536779129128751443593956",
                "25958808570964749784639268294899051561",
                "169906310694726979804068082261979013275",
                "183623048638044105492562068017371543485",
                "142276825032818657019505045178018461125",
                "268038886482406467953963465038444011578",
                "271015781678970494494185172993673686146",
                "330198691366869673593327999239520949120",
                "122335371543187787535858525132366353749",
                "36595750303080337720196958931636279021",
                "64849755753255886746871143036872632056",
                "80014235998608291661546150543580851435",
                "44276092994165310507522064688793441660",
                "210277867427717858103008806350725749966"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/4bbde8c50c00bc572578ab2cff609b3443d10ddf",
        "id": "CVE-2023-37262-563343fb",
        "target": {
            "file": "projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "33426211174991107262644437541840483897",
                "82026089675691307145947323444898591005",
                "135179369464140838882575988948292458323",
                "246345997171395874465909669765123173484"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/4bbde8c50c00bc572578ab2cff609b3443d10ddf",
        "id": "CVE-2023-37262-8024a09b",
        "target": {
            "file": "projects/core/src/test/java/dan200/computercraft/core/apis/http/options/AddressRuleTest.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 22.0,
            "function_hash": "45178275718944758447062834043860974696"
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
        "id": "CVE-2023-37262-e82992b6",
        "target": {
            "function": "go2",
            "file": "projects/core/src/test/java/dan200/computercraft/core/asm/MethodTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "122167524853676315694559795902660152304",
                "21877929789351810741453383542162775444",
                "3583012578804011656921950830924644948",
                "262086829505503992149696135673051423090",
                "300677439875451556365413534098290865129",
                "136720767535167183398501602226905406542",
                "41481568801462181263391448881101940870",
                "285545849470295235335653818457577456602"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
        "id": "CVE-2023-37262-eda0ebc3",
        "target": {
            "file": "projects/core/src/test/java/dan200/computercraft/core/asm/MethodTest.java"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37262.json"