VDB

CVE-2022-1231

CVE-2022-1231 PUBLISHED CVSS 9.300000190734863 CRITICAL

XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).

EPSS 1.83% · 77.3th percentile

Risk Scores

CVSS 3.0
9.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
EPSS Score
1.83%
77.3th percentile

Affected Products

VendorProductVersions
plantumlplantuml/plantuml*
fedoraprojectfedora35, 36
plantumlplantuml0

Timeline

  • Apr 15, 2022 CVE Published
  • Apr 16, 2022 EPSS Score
  • Apr 23, 2022 EPSS Score
  • Apr 27, 2022 EPSS Score
  • Jun 5, 2022 EPSS Score
  • Sep 15, 2022 EPSS Score
  • Nov 4, 2022 EPSS Score
  • Dec 24, 2022 EPSS Score
  • Feb 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 4, 2023 EPSS Score
  • May 24, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›