-
Bug
-
Resolution: Unresolved
-
None
-
Minecraft 17w06a, Minecraft 17w14a, Minecraft 17w15a, Minecraft 1.12.2, 1.15.1, 1.15.2, 1.16 Release Candidate 1, 1.16, 1.16.1, 20w28a, 20w29a, 20w30a, 1.16.2 Pre-release 1, 1.16.2 Pre-release 2, 1.16.2 Pre-release 3, 1.16.2 Release Candidate 1, 1.16.2 Release Candidate 2, 1.16.2, 1.16.3 Release Candidate 1, 1.16.3, 1.16.4 Pre-release 1, 1.16.4 Pre-release 2, 1.16.4 Release Candidate 1, 1.16.4, 20w45a, 20w46a, 20w48a, 20w49a, 20w51a, 21w03a, 21w05b, 21w06a, 21w07a, 21w08b, 21w10a, 21w11a, 21w13a, 21w14a, 21w39a, 22w06a, 22w14a, 1.19.2, 1.19.3, 1.19.4, 23w51b
-
Confirmed
-
Creative
-
UI
-
Important
-
Platform
The bug
When restoring toolbars, items that are normally unobtainable through the creative inventory without the use of commands can be obtained. This can be used by players with creative mode but without operator status on servers to obtain items like dragon eggs, command blocks, structure blocks, and more.
Steps to reproduce
- In a world in which you have operator privileges, save a toolbar with dragon eggs, structure blocks, and command blocks, as well as some dirt and other items that are obtainable through the creative inventory
- Join a server on which you have creative mode (operator privileges are not required)
- Restore the toolbar, even without operator privileges
Behaviour
You will see that when you follow these reproduction steps, every item is restored, including the dragon eggs, structure blocks, and command blocks. The expected behaviour is that only the items obtainable without the use of commands would be restored.
- is duplicated by
-
MC-118935 Saving creative hotbars in 1.12
- Resolved
-
MC-131692 Saved Toolbars Exploit
- Resolved
-
MC-190471 Toolbars allows players to get illegal items
- Resolved
-
MC-258952 You can get operator items without operator permissions when you are in creative mode
- Resolved
- relates to
-
MC-190478 Commands that exceed chat length limit can still be executed in servers that have disabled command blocks
- Reopened