CVE-2022-1379
published 2022-05-14CVE-2022-1379: URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.55%
72.5th percentile
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | plantuml | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| plantuml | plantuml | < 1.2022.5 | 1.2022.5 |
| plantuml | plantuml_plantuml | >= unspecified < V1.2022.5 | V1.2022.5 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8qqf-jx6g-2rcv: URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1
ghsa_unreviewed·2022-05-15
CVE-2022-1379 [CRITICAL] CWE-918 GHSA-8qqf-jx6g-2rcv: URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.
OSV
CVE-2022-1379: URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1
osv·2022-05-14·CVSS 9.1
CVE-2022-1379 [CRITICAL] CVE-2022-1379: URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.
Debian
CVE-2022-1379: plantuml - URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5...
vendor_debian·2022·CVSS 9.1
CVE-2022-1379 [CRITICAL] CVE-2022-1379: plantuml - URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5...
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/plantuml/plantuml/commit/93e5964e5f35914f3f7b89de620c596795550083https://huntr.dev/bounties/0d737527-86e1-41d1-9d37-b2de36bc063ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHUE4G5CAJUD7L2QPJF6U4JYQTP7CNNL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4DP36G2VBOZUNQIUZ5LVJKZIVO4SDAI/https://github.com/plantuml/plantuml/commit/93e5964e5f35914f3f7b89de620c596795550083https://huntr.dev/bounties/0d737527-86e1-41d1-9d37-b2de36bc063ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHUE4G5CAJUD7L2QPJF6U4JYQTP7CNNL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4DP36G2VBOZUNQIUZ5LVJKZIVO4SDAI/
2022-05-14
Published