Medium severity5.3NVD Advisory· Published May 28, 2019· Updated Jun 17, 2026
CVE-2019-12395
CVE-2019-12395
Description
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:dynmap_project:dynmap:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:dynmap_project:dynmap:*:*:*:*:*:*:*:*range: <3.0
- cpe:2.3:a:dynmap_project:dynmap:3.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:dynmap_project:dynmap:3.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:dynmap_project:dynmap:3.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:dynmap_project:dynmap:3.0:rc3:*:*:*:*:*:*
- Webbukkit/Dynmapdescription
Patches
Vulnerability mechanics
References
4- github.com/webbukkit/dynmap/commit/641f142cd3ccdcbfb04eda3059be22dd9ed93783nvdPatchThird Party Advisory
- github.com/webbukkit/dynmap/pull/2475nvdPatchThird Party Advisory
- github.com/webbukkit/dynmap/issues/2474nvdExploitIssue TrackingThird Party Advisory
- jvn.jp/en/jp/JVN89046645/index.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.