CVE-2023-35925

MEDIUM

FastAsyncWorldEdit < 2.6.3 - Denial of Service via Infinity Region Selection

Title source: llm
STIX 2.1

Description

FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibility of bringing the performing server down. This issue has been fixed in version 2.6.3.

Scores

CVSS v3 6.2
EPSS 0.0031
EPSS Percentile 22.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (3)
com.fastasyncworldedit/FastAsyncWorldEdit-Bukkit 0 - 2.6.3Maven
com.fastasyncworldedit/FastAsyncWorldEdit-Core 0 - 2.6.3Maven
intellectualsites/fastasyncworldedit < 2.6.3
Published Jun 23, 2023
Tracked Since Feb 18, 2026