Skip to content

[Vulnerability] Fix Bleeding Pipe vulnerability using SerializationIsBad #145

@cuberyl-catastrophe

Description

@cuberyl-catastrophe

Context

This vulnerability has also been pointed out in #140

https://github.com/dogboy21/serializationisbad/blob/master/README.md
Around 2023, a vulnerability that allows for remote code execution was found in many 1.12 mods including /dank/null and EnderCore. This makes this modpack unsafe to play in multiplayer unless a patcher mod is added like SerializationIsBad.

EnderCore has an update that fixes the vulnerability but there has been no update for /dank/null so the only fix for that is to add a patcher.

The recommended fix for this is to add the SerializationIsBad mod to the pack.

Metadata

Metadata

Assignees

Labels

Enhancement: NewA new enhancement by modpack players

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions