VDB
CVE-2022-1231
CVE-2022-1231
PUBLISHED
CVSS 9.300000190734863 CRITICAL
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).
EPSS 1.83% · 77.3th percentile
Risk Scores
CVSS 3.0
9.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
EPSS Score
1.83%
77.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| plantuml | plantuml/plantuml | * |
| fedoraproject | fedora | 35, 36 |
| plantuml | plantuml | 0 |
Timeline
- Apr 15, 2022 CVE Published
- Apr 16, 2022 EPSS Score
- Apr 23, 2022 EPSS Score
- Apr 27, 2022 EPSS Score
- Jun 5, 2022 EPSS Score
- Sep 15, 2022 EPSS Score
- Nov 4, 2022 EPSS Score
- Dec 24, 2022 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 24, 2023 EPSS Score
References
- https://huntr.dev/bounties/27db9509-6cd3-4148-8d70-5942f3837604 url
- https://github.com/plantuml/plantuml/commit/c9137be051ce98b3e3e27f65f54ec7d9f8886903 url
- FEDORA-2022-e8b1324ec8 vendor-advisory
- FEDORA-2022-930b54aa84 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1231 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EO26WBHQRMWTS44M5VLZJIJZOIGJYL3A url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FQMHXN5BVBK433C5SVSSBXWB5JLJ7NID url