CVE-2022-1379
Summary
| CVE | CVE-2022-1379 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-14 10:15:00 UTC |
| Updated | 2023-11-07 03:41:00 UTC |
| Description | URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| URL Restriction Bypass vulnerability found in plantuml |
CONFIRM |
huntr.dev |
|
| [SECURITY] Fedora 35 Update: plantuml-1.2022.5-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Import version 1.2022.5 · plantuml/plantuml@93e5964 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: plantuml-1.2022.5-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: plantuml-1.2022.5-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: plantuml-1.2022.5-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 282755 Fedora Security Update for plantuml (FEDORA-2022-e6c09a89eb)
- 282759 Fedora Security Update for plantuml (FEDORA-2022-fda9f1f7bd)