Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection. https://github.com/minetest/minetest/security/advisories/GHSA-hwj2-xf72-r4cf https://github.com/minetest/minetest/commit/b5956bde259faa240a81060ff4e598e25ad52dae https://bugs.debian.org/1004223
Created minetest tracking bugs for this issue: Affects: epel-all [bug 2050044] Affects: fedora-all [bug 2050043]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.