Vulnerability Description
FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibility of bringing the performing server down. This issue has been fixed in version 2.6.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intellectualsites | Fastasyncworldedit | < 2.6.3 |
Related Weaknesses (CWE)
References
- https://github.com/IntellectualSites/FastAsyncWorldEdit/pull/2285Patch
- https://github.com/IntellectualSites/FastAsyncWorldEdit/releases/tag/2.6.3Release Notes
- https://github.com/IntellectualSites/FastAsyncWorldEdit/security/advisories/GHSAVendor Advisory
- https://github.com/IntellectualSites/FastAsyncWorldEdit/pull/2285Patch
- https://github.com/IntellectualSites/FastAsyncWorldEdit/releases/tag/2.6.3Release Notes
- https://github.com/IntellectualSites/FastAsyncWorldEdit/security/advisories/GHSAVendor Advisory
FAQ
What is CVE-2023-35925?
CVE-2023-35925 is a vulnerability with a CVSS score of 6.2 (MEDIUM). FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. ...
How severe is CVE-2023-35925?
CVE-2023-35925 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-35925?
Check the references section above for vendor advisories and patch information. Affected products include: Intellectualsites Fastasyncworldedit.