CVE-2023-3431
Publication date 27 June 2023
Last updated 17 March 2025
Ubuntu priority
Cvss 3 Severity Score
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
Status
Package | Ubuntu Release | Status |
---|---|---|
plantuml | 24.10 oracular | Ignored backport too intrusive |
24.04 LTS noble | Ignored backport too intrusive | |
22.04 LTS jammy | Ignored backport too intrusive | |
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Ignored end of standard support |
Notes
john-breton
ALLOW_INCLUDE defaulting to false was not introduced prior to 1.2020.X. Prior to version 1.2020.11, the security module of PlantUML did not exist. This fix relies on this module and its adoption requires significant code changes, making a backport infeasible.
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | Low |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |