CVE-2023-35925 MEDIUM

CVE-2023-35925: FastAsyncWorldEdit vulnerable to Uncontrolled Resource Consumption

Vendor Intellectualsites
Product FastAsyncWorldEdit
Weakness CWE-400
Published June 23, 2023
Last update November 27, 2024

CVSS base score

6.2/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibility of bringing the performing server down. This issue has been fixed in version 2.6.3.

Key dates

02Disclosure timeline

June 23, 2023 CVE published
November 27, 2024 Record updated