VYPR
Medium severity5.3NVD Advisory· Published May 28, 2019· Updated Jun 17, 2026

CVE-2019-12395

CVE-2019-12395

Description

In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:dynmap_project:dynmap:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:dynmap_project:dynmap:*:*:*:*:*:*:*:*range: <3.0
    • cpe:2.3:a:dynmap_project:dynmap:3.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:dynmap_project:dynmap:3.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:dynmap_project:dynmap:3.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:dynmap_project:dynmap:3.0:rc3:*:*:*:*:*:*
  • Webbukkit/Dynmapdescription
  • Webbukkit/Dynmapllm-fuzzy
    Range: <=3.0-beta-3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.