CVE-2021-37632 affects SuperMartijn642's Config Lib versions 1.0.4 to 1.0.8, a Minecraft mod library, due to insecure deserialization (CWE-502) where ObjectInputStream#readObject is used to process unvalidated packet data. This allows an unauthenticated attacker to instantiate arbitrary classes by sending a malicious packet, potentially leading to remote code execution on both clients and servers. With a CVSS score of 8.1 (High), the vulnerability is remotely exploitable with high impact on confidentiality, integrity, and availability, though with high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.4, < 1.0.9CPE matchmatch criteria | cpe:2.3:a:config_lib_project:config_lib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.