cbcvebase.
CVE-2022-1379
published 2022-05-14

CVE-2022-1379: URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the…

PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.55%
72.5th percentile
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianplantuml
fedoraprojectfedora
fedoraprojectfedora
plantumlplantuml< 1.2022.51.2022.5
plantumlplantuml_plantuml>= unspecified < V1.2022.5V1.2022.5

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.