kangarko / ChatControl-Red

Issue tracker and documentation for the next generation ChatControl Red, the most advanced chat management plugin.
43 stars 22 forks source link

1.20: Vulnerability? #2682

Closed joshwenke closed 1 month ago

joshwenke commented 1 month ago

Are you using MySQL?

Yes

Are you using BungeeCord/Velocity?

Yes - BungeeCord

Question

Hello, we are looking at using the forward command, but it has mentioned a potential vulnerability for several months. Can you share more details on this?

image

kangarko commented 1 month ago

Details here: https://github.com/kangarko/ChatControl-Red/issues/2664

I believe it's safe now but I did not get around to make a custom hacked client to test this. We switched to broadcast on BungeeCord channel which afaik is ignored when not coming from server connection and we do an extra check to ignore players.