CVE-2022-1231
published 2022-04-15CVE-2022-1231: XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder…
PriorityP430medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.83%
76.5th percentile
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | plantuml | < plantuml 1:1.2020.2+ds-6 (forky) | plantuml 1:1.2020.2+ds-6 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| plantuml | plantuml | < 1.2022.4 | 1.2022.4 |
| plantuml | plantuml | >= 0 < 1:1.2020.2+ds-6 | 1:1.2020.2+ds-6 |
| plantuml | plantuml | >= 0 < 1:1.2020.2+ds-6 | 1:1.2020.2+ds-6 |
| plantuml | plantuml_plantuml | >= unspecified < 1.2022.4 | 1.2022.4 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.09.3CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PlantUML vulnerability
vendor_ubuntu·2025-03-17
CVE-2022-1231 PlantUML vulnerability
Title: PlantUML vulnerability
Summary: PlantUML could be made to crash or run programs as your login if it
opened a specially crafted UML file.
Tobias S. Fink discovered that PlantUML was susceptible to cross-site
scripting attacks (XSS) in instances where SVG images were rendered.
An attacker could possibly use this issue to cause PlantUML to crash,
resulting in a denial of service, or the execution of arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-1231: plantuml - XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantum...
vendor_debian·2022·CVSS 6.1
CVE-2022-1231 [MEDIUM] CVE-2022-1231: plantuml - XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantum...
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.2020.2+ds-6)
sid: resolved (fixed in 1:1.2020.2+ds-6)
trixie: resolved (fixed in 1:1.2020.2+ds-6)
GHSA
GHSA-cpj6-8368-p538: XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1
ghsa_unreviewed·2022-04-16
CVE-2022-1231 [MEDIUM] CWE-79 GHSA-cpj6-8368-p538: XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).
OSV
CVE-2022-1231: XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1
osv·2022-04-15·CVSS 6.1
CVE-2022-1231 [MEDIUM] CVE-2022-1231: XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/plantuml/plantuml/commit/c9137be051ce98b3e3e27f65f54ec7d9f8886903https://huntr.dev/bounties/27db9509-6cd3-4148-8d70-5942f3837604https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EO26WBHQRMWTS44M5VLZJIJZOIGJYL3A/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FQMHXN5BVBK433C5SVSSBXWB5JLJ7NID/https://github.com/plantuml/plantuml/commit/c9137be051ce98b3e3e27f65f54ec7d9f8886903https://huntr.dev/bounties/27db9509-6cd3-4148-8d70-5942f3837604https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EO26WBHQRMWTS44M5VLZJIJZOIGJYL3A/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FQMHXN5BVBK433C5SVSSBXWB5JLJ7NID/
2022-04-15
Published