SleepyTrousers / EnderCore

Library mod used by EnderIO, EnderZoo, and others
Creative Commons Zero v1.0 Universal
50 stars 71 forks source link

Major Vulnerability #142

Closed RealmKebab closed 11 months ago

RealmKebab commented 11 months ago

Your mod has a vulnerability, it affects versions 1.9-1.13.2 (according to serialization is bad), because your mod is popular, people may download your mod without notice this is a huge major vulnerability. I advise you fix it immediately https://github.com/dogboy21/serializationisbad https://blog.mmpa.info/posts/bleeding-pipe/

tyler489 commented 11 months ago

I would advise you to check the last patch https://github.com/SleepyTrousers/EnderCore/commit/76170fc31be2aff3798ccf04fb51820eaef5abe8

RealmKebab commented 11 months ago

I would advise you to check the last patch 76170fc

ah alright, i got confused on why the guy was spamming pull requests lol