CVE-2023-3431

Name
CVE-2023-3431
Description
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://huntr.dev/bounties/fa741f95-b53c-4ed7-b157-e32c5145164c
MISC https://github.com/plantuml/plantuml/commit/fbe7fa3b25b4c887d83927cffb1009ec6cb8ab1e
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FV7XL3CY3K3K5ER3ASMEQA546MIQQ7QM/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:plantuml:plantuml:*:*:*:*:*:*:*:* plantuml >= None < 1.2023.9

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
plantuml 3.18-community 1.2023.6-r0 Krystian ChachuĊ‚a <krystian@krystianch.com> possibly vulnerable