CVE-2022-29215 is a YAML injection vulnerability affecting versions of the RegionProtect plugin prior to 1.1.0, which allows users to manage in-game regions. An unauthenticated attacker can trigger a server crash by providing malformed arguments, resulting in a high availability impact. While the vulnerability has a CVSS score of 7.5 (High), there is no evidence of active exploitation, public exploit code, or significant community discussion. A patch is available in version 1.1.0, and a workaround involves restricting operator permissions and avoiding suspicious argument input.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.0CPE matchmatch criteria | cpe:2.3:a:regionprotect_project:regionprotect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.