CVE-2023-3431: Improper Access Control in plantuml/plantuml
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/net.sourceforge.plantuml:plantuml-mitto a version that resolves this vulnerability.Fixed in 1.2023.9
Event History
Frequently Asked Questions
What is CVE-2023-3431?
CVE-2023-3431 refers to the vulnerability titled 'Improper Access Control' in the GitHub repository plantuml/plantuml prior to version 1.2023.9.
What is the severity of CVE-2023-3431?
CVE-2023-3431 has a severity level of 5.3 (Medium).
How does CVE-2023-3431 affect the software?
CVE-2023-3431 affects the GitHub repository plantuml/plantuml prior to version 1.2023.9 and the Maven package 'net.sourceforge.plantuml:plantuml-mit' up to version 1.2023.9.
How can I fix CVE-2023-3431?
To fix CVE-2023-3431, you should update the affected software to version 1.2023.9 or later.
Where can I find more information about CVE-2023-3431?
You can find more information about CVE-2023-3431 at the following references: [Reference 1](https://github.com/plantuml/plantuml/commit/fbe7fa3b25b4c887d83927cffb1009ec6cb8ab1e), [Reference 2](https://huntr.dev/bounties/fa741f95-b53c-4ed7-b157-e32c5145164c), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FV7XL3CY3K3K5ER3ASMEQA546MIQQ7QM/).