CVE-2024-56141
Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b046a490026a8413b075685deb795122, the CryptManager encryption routine ( CryptManager.kt ) initializes its AES cipher using an initialization vector (IV) that is set equal to the secret key rather than to a sufficiently random value. Because the IV is not random and is derived directly from the key, the encryption is vulnerable to chosen-ciphertext/chosen-plaintext attacks: an attacker who can submit specific messages for encryption can recover the secret key. This affects all versions supporting Minecraft protocol 1.7 and later. No patched version is available, and no known workarounds are available.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-329
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-56141",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-56141",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-08T17:48:31.002750Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "Bixilon",
"product": "Minosoft",
"versions": [
{
"status": "affected",
"version": ">= f1ae30e2b046a490026a8413b075685deb795122"
}
]
}
]
}
],
"published": "2026-07-07T00:16:33.607",
"references": [
{
"url": "https://github.com/Bixilon/Minosoft/blob/3a608abe2d0999e4e702cc1b2d28366884c7f31e/src/main/java/de/bixilon/minosoft/protocol/protocol/encryption/CryptManager.kt#L72",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Bixilon/Minosoft/security/advisories/GHSA-rvr6-48rj-c94j",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-329"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b046a490026a8413b075685deb795122, the CryptManager encryption routine ( CryptManager.kt ) initializes its AES cipher using an initialization vector (IV) that is set equal to the secret key rather than to a sufficiently random value. Because the IV is not random and is derived directly from the key, the encryption is vulnerable to chosen-ciphertext/chosen-plaintext attacks: an attacker who can submit specific messages for encryption can recover the secret key. This affects all versions supporting Minecraft protocol 1.7 and later. No patched version is available, and no known workarounds are available."
},
{
"lang": "es",
"value": "Minosoft es un cliente de Minecraft Java Edition de código abierto y multiversión, escrito en Kotlin. A partir del commit f1ae30e2b046a490026a8413b075685deb795122, la rutina de cifrado CryptManager ( CryptManager.kt ) inicializa su cifrador AES utilizando un vector de inicialización (IV) que se establece igual a la clave secreta en lugar de a un valor suficientemente aleatorio. Debido a que el IV no es aleatorio y se deriva directamente de la clave, el cifrado es vulnerable a ataques de texto cifrado elegido/texto plano elegido: un atacante que puede enviar mensajes específicos para el cifrado puede recuperar la clave secreta. Esto afecta a todas las versiones que soportan el protocolo de Minecraft 1.7 y posteriores. No hay una versión parcheada disponible, y no hay soluciones alternativas conocidas disponibles."
}
],
"lastModified": "2026-10-02T00:10:00.180",
"sourceIdentifier": "security-advisories@github.com"
}