// For flags

CVE-2022-35978

Lua sandbox escape from mod in Minetest

Severity Score

10.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.

Minetest es un motor de juegos voxel de código abierto que permite modificar y crear juegos fácilmente. En **single player**, un mod puede establecer una configuración global que controla el script Lua cargado para mostrar el menú principal. El script es cargado en cuanto sale de la sesión de juego. El entorno Lua en el que es ejecutado el menú no está aislado y puede interferir directamente con el sistema del usuario. Actualmente no se presentan mitigaciones conocidas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-07-15 CVE Reserved
  • 2022-08-15 CVE Published
  • 2024-04-05 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-693: Protection Mechanism Failure
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Minetest
Search vendor "Minetest"
Minetest
Search vendor "Minetest" for product "Minetest"
< 5.6.0
Search vendor "Minetest" for product "Minetest" and version " < 5.6.0"
-
Affected