CVE-2024-41565 describes an Improper Validation of Specified Index, Position, or Offset vulnerability in JustEnoughItems (JEI) 19.5.0.33 and earlier, a Minecraft mod. This flaw allows in-game item duplication due to a failure to validate slot indices within JEI. With a CVSS score of 5.3 (Medium), the vulnerability is network-exploitable with low attack complexity and no user interaction required, leading to a low impact on integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.6.0.1021CPE matchmatch criteria | cpe:2.3:a:mezz:justenoughitems:*:*:*:*:*:minecraft:*:* | ||
>= 12.0.0, < 13.1.0.18CPE matchmatch criteria | cpe:2.3:a:mezz:justenoughitems:*:*:*:*:*:minecraft:*:* | ||
>= 14.0.0, < 15.8.0.11CPE matchmatch criteria | cpe:2.3:a:mezz:justenoughitems:*:*:*:*:*:minecraft:*:* | ||
>= 16.0.0, < 19.5.0.34CPE matchmatch criteria | cpe:2.3:a:mezz:justenoughitems:*:*:*:*:*:minecraft:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.