CVE-2023-3432: Server-Side Request Forgery (SSRF) in plantuml/plantuml
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/net.sourceforge.plantuml:plantumlto a version that resolves this vulnerability.Fixed in 1.2023.9 - Upgrade
Upgrade
maven/net.sourceforge.plantuml:plantuml-mitto a version that resolves this vulnerability.Fixed in 1.2023.9
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3432?
CVE-2023-3432 is classified as a high severity vulnerability due to its exploitation potential through Server-Side Request Forgery (SSRF).
How do I fix CVE-2023-3432?
To fix CVE-2023-3432, upgrade to version 1.2023.9 or later of the affected PlantUML software.
Which versions are affected by CVE-2023-3432?
CVE-2023-3432 affects all versions of PlantUML prior to 1.2023.9.
What type of vulnerability is CVE-2023-3432?
CVE-2023-3432 is a Server-Side Request Forgery (SSRF) vulnerability.
Is CVE-2023-3432 applicable to Fedora users?
Yes, CVE-2023-3432 is applicable to users of Fedora 39 who are using the affected versions of PlantUML.