CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to versions 1.20.1-1.106.0, 1.19.4-1.106.0, 1.19.2-1.101.3, 1.18.2-1.101.3, and 1.16.5-1.101.3, if the cc-tweaked plugin is running on a Minecraft server hosted on a popular cloud hosting providers, like AWS, GCP, and Azure, those metadata services API endpoints are not forbidden (aka "blacklisted") by default. As such, any player can gain access to sensitive information exposed via those metadata servers, potentially allowing them to pivot or privilege escalate into the hosting provider. Versions 1.20.1-1.106.0, 1.19.4-1.106.0, 1.19.2-1.101.3, 1.18.2-1.101.3, and 1.16.5-1.101.3 contain a fix for this issue.
{
"cwe_ids": [
"CWE-918"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37262.json"
}{
"cpe": "cpe:2.3:a:tweaked:cc-tweaked:*:*:*:*:*:minecraft:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.16.5-1.101.3"
},
{
"introduced": "1.17.1-1.98.1"
},
{
"fixed": "1.18.2-1.101.3"
},
{
"introduced": "1.19.1-1.100.9"
},
{
"fixed": "1.19.2-1.101.3"
},
{
"introduced": "1.19.3-1.102.0"
},
{
"fixed": "1.19.4-1.106.0"
},
{
"introduced": "1.20.1-1.105.0"
},
{
"fixed": "1.20.1-1.106.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-22T02:25:24Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 154.0,
"function_hash": "48939138621218488815824292088523064708"
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
"id": "CVE-2023-37262-0154001c",
"target": {
"function": "testExtra",
"file": "projects/core/src/test/java/dan200/computercraft/core/asm/MethodTest.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"180144484903901506208089478192765426312",
"334659197182951094034655171936497399415",
"232964441626505346179137990738064291507",
"258529733809329783191523140932297187643"
]
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
"id": "CVE-2023-37262-06f206d2",
"target": {
"file": "projects/core/src/main/java/dan200/computercraft/core/asm/MethodSupplierImpl.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 765.0,
"function_hash": "97912784879334948814938950326261085838"
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
"id": "CVE-2023-37262-0d8590bd",
"target": {
"function": "forEachMethod",
"file": "projects/core/src/main/java/dan200/computercraft/core/asm/MethodSupplierImpl.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 136.0,
"function_hash": "301979240058404626912808031733699886564"
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/4bbde8c50c00bc572578ab2cff609b3443d10ddf",
"id": "CVE-2023-37262-38efc77b",
"target": {
"function": "matches",
"file": "projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"125240597833634536779129128751443593956",
"25958808570964749784639268294899051561",
"169906310694726979804068082261979013275",
"183623048638044105492562068017371543485",
"142276825032818657019505045178018461125",
"268038886482406467953963465038444011578",
"271015781678970494494185172993673686146",
"330198691366869673593327999239520949120",
"122335371543187787535858525132366353749",
"36595750303080337720196958931636279021",
"64849755753255886746871143036872632056",
"80014235998608291661546150543580851435",
"44276092994165310507522064688793441660",
"210277867427717858103008806350725749966"
]
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/4bbde8c50c00bc572578ab2cff609b3443d10ddf",
"id": "CVE-2023-37262-563343fb",
"target": {
"file": "projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"33426211174991107262644437541840483897",
"82026089675691307145947323444898591005",
"135179369464140838882575988948292458323",
"246345997171395874465909669765123173484"
]
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/4bbde8c50c00bc572578ab2cff609b3443d10ddf",
"id": "CVE-2023-37262-8024a09b",
"target": {
"file": "projects/core/src/test/java/dan200/computercraft/core/apis/http/options/AddressRuleTest.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 22.0,
"function_hash": "45178275718944758447062834043860974696"
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
"id": "CVE-2023-37262-e82992b6",
"target": {
"function": "go2",
"file": "projects/core/src/test/java/dan200/computercraft/core/asm/MethodTest.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"122167524853676315694559795902660152304",
"21877929789351810741453383542162775444",
"3583012578804011656921950830924644948",
"262086829505503992149696135673051423090",
"300677439875451556365413534098290865129",
"136720767535167183398501602226905406542",
"41481568801462181263391448881101940870",
"285545849470295235335653818457577456602"
]
},
"signature_version": "v1",
"source": "https://github.com/cc-tweaked/cc-tweaked/commit/9ea7f45fa7395eac8a6bdcad04e46e14bde5db9b",
"id": "CVE-2023-37262-eda0ebc3",
"target": {
"file": "projects/core/src/test/java/dan200/computercraft/core/asm/MethodTest.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37262.json"