5.3

CVE-2019-12395

Exploit
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dynmap ProjectDynmap Version < 3.0
Dynmap ProjectDynmap Version3.0 Updatealpha1
Dynmap ProjectDynmap Version3.0 Updatealpha2
Dynmap ProjectDynmap Version3.0 Updatealpha3
Dynmap ProjectDynmap Version3.0 Updaterc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.6% 0.726
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://jvn.jp/en/jp/JVN89046645/index.html
Third Party Advisory
https://github.com/webbukkit/dynmap/commit/641f142cd3ccdcbfb04eda3059be22dd9ed93783
Patch
Third Party Advisory
https://github.com/webbukkit/dynmap/issues/2474
Third Party Advisory
Exploit
Issue Tracking
https://github.com/webbukkit/dynmap/pull/2475
Patch
Third Party Advisory