{"id":"GHSA-p2mf-q26j-3xmh","summary":"PlantUML Improper Access Control vulnerability","details":"Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.","aliases":["CVE-2023-3431"],"modified":"2024-02-20T05:18:02.534454Z","published":"2023-06-27T15:30:28Z","database_specific":{"github_reviewed_at":"2023-06-27T17:15:10Z","nvd_published_at":"2023-06-27T15:15:11Z","cwe_ids":["CWE-284"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3431"},{"type":"WEB","url":"https://github.com/plantuml/plantuml/commit/fbe7fa3b25b4c887d83927cffb1009ec6cb8ab1e"},{"type":"PACKAGE","url":"https://github.com/plantuml/plantuml"},{"type":"WEB","url":"https://huntr.dev/bounties/fa741f95-b53c-4ed7-b157-e32c5145164c"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FV7XL3CY3K3K5ER3ASMEQA546MIQQ7QM"}],"affected":[{"package":{"name":"net.sourceforge.plantuml:plantuml-mit","ecosystem":"Maven","purl":"pkg:maven/net.sourceforge.plantuml/plantuml-mit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2023.9"}]}],"versions":["1.2023.7","1.2023.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-p2mf-q26j-3xmh/GHSA-p2mf-q26j-3xmh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}