PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file is not automatically uploaded or shared, if the user manually sends the log file, there is a risk of leakage. This is fixed in version 2.12.0-beta.10.
History

Wed, 23 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Pcl
Pcl pcl2-ce
Vendors & Products Pcl
Pcl pcl2-ce

Wed, 23 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file is not automatically uploaded or shared, if the user manually sends the log file, there is a risk of leakage. This is fixed in version 2.12.0-beta.10.
Title PCL Community Edition exposes login credentials in logs
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-23T00:11:58.870Z

Updated: 2025-07-23T15:14:46.562Z

Reserved: 2025-07-16T23:53:40.508Z

Link: CVE-2025-54120

cve-icon Vulnrichment

Updated: 2025-07-23T14:31:14.428Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-23T01:15:24.203

Modified: 2025-07-25T15:29:44.523

Link: CVE-2025-54120

cve-icon Redhat

No data.