Vulnerability Details CVE-2021-33806
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.069
EPSS Ranking 90.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-33806
-
-
cpe:2.3:a:bdew:bdlib:0.9.0
-
cpe:2.3:a:bdew:bdlib:0.9.1
-
cpe:2.3:a:bdew:bdlib:0.9.2
-
cpe:2.3:a:bdew:bdlib:0.9.3
-
cpe:2.3:a:bdew:bdlib:0.9.4
-
cpe:2.3:a:bdew:bdlib:0.9.5
-
cpe:2.3:a:bdew:bdlib:1.0.0
-
cpe:2.3:a:bdew:bdlib:1.0.1
-
cpe:2.3:a:bdew:bdlib:1.1.0
-
cpe:2.3:a:bdew:bdlib:1.16.1.6
-
cpe:2.3:a:bdew:bdlib:1.2.0
-
cpe:2.3:a:bdew:bdlib:1.2.1
-
cpe:2.3:a:bdew:bdlib:1.2.2
-
cpe:2.3:a:bdew:bdlib:1.2.3
-
cpe:2.3:a:bdew:bdlib:1.3.0
-
cpe:2.3:a:bdew:bdlib:1.4.0
-
cpe:2.3:a:bdew:bdlib:1.4.1
-
cpe:2.3:a:bdew:bdlib:1.4.2
-
cpe:2.3:a:bdew:bdlib:1.4.3
-
cpe:2.3:a:bdew:bdlib:1.4.4
-
cpe:2.3:a:bdew:bdlib:1.4.5
-
cpe:2.3:a:bdew:bdlib:1.5.0
-
cpe:2.3:a:bdew:bdlib:1.5.1
-
cpe:2.3:a:bdew:bdlib:1.6.0
-
cpe:2.3:a:bdew:bdlib:1.6.1
-
cpe:2.3:a:bdew:bdlib:1.6.2
-
cpe:2.3:a:bdew:bdlib:1.6.3
-
cpe:2.3:a:bdew:bdlib:1.6.4
-
cpe:2.3:a:bdew:bdlib:1.6.5
-
cpe:2.3:a:bdew:bdlib:1.7.0
-
cpe:2.3:a:bdew:bdlib:1.7.1
-
cpe:2.3:a:bdew:bdlib:1.8.0
-
cpe:2.3:a:bdew:bdlib:1.8.1
-
cpe:2.3:a:bdew:bdlib:1.8.2
-
cpe:2.3:a:bdew:bdlib:1.9.0
-
cpe:2.3:a:bdew:bdlib:1.9.1
-
cpe:2.3:a:bdew:bdlib:1.9.2
-
cpe:2.3:a:bdew:bdlib:1.9.3
-
cpe:2.3:a:bdew:bdlib:1.9.4