{"api_version":"1","generated_at":"2026-07-23T12:07:09+00:00","cve":"CVE-2022-1379","urls":{"html":"https://cve.report/CVE-2022-1379","api":"https://cve.report/api/cve/CVE-2022-1379.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-1379","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-1379"},"summary":{"title":"CVE-2022-1379","description":"URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.","state":"PUBLIC","assigner":"security@huntr.dev","published_at":"2022-05-14 10:15:00","updated_at":"2023-11-07 03:41:00"},"problem_types":["CWE-918"],"metrics":[],"references":[{"url":"https://huntr.dev/bounties/0d737527-86e1-41d1-9d37-b2de36bc063a","name":"https://huntr.dev/bounties/0d737527-86e1-41d1-9d37-b2de36bc063a","refsource":"CONFIRM","tags":[],"title":"URL Restriction Bypass  vulnerability found in plantuml","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4DP36G2VBOZUNQIUZ5LVJKZIVO4SDAI/","name":"FEDORA-2022-fda9f1f7bd","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: plantuml-1.2022.5-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/plantuml/plantuml/commit/93e5964e5f35914f3f7b89de620c596795550083","name":"https://github.com/plantuml/plantuml/commit/93e5964e5f35914f3f7b89de620c596795550083","refsource":"MISC","tags":[],"title":"Import version 1.2022.5 · plantuml/plantuml@93e5964 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J4DP36G2VBOZUNQIUZ5LVJKZIVO4SDAI/","name":"FEDORA-2022-fda9f1f7bd","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: plantuml-1.2022.5-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHUE4G5CAJUD7L2QPJF6U4JYQTP7CNNL/","name":"FEDORA-2022-e6c09a89eb","refsource":"","tags":[],"title":"[SECURITY] Fedora 36 Update: plantuml-1.2022.5-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHUE4G5CAJUD7L2QPJF6U4JYQTP7CNNL/","name":"FEDORA-2022-e6c09a89eb","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 36 Update: plantuml-1.2022.5-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-1379","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1379","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"1379","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"1379","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"1379","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"plantuml","cpe5":"plantuml","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-1379","qid":"282755","title":"Fedora Security Update for plantuml (FEDORA-2022-e6c09a89eb)"},{"cve":"CVE-2022-1379","qid":"282759","title":"Fedora Security Update for plantuml (FEDORA-2022-fda9f1f7bd)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@huntr.dev","ID":"CVE-2022-1379","STATE":"PUBLIC","TITLE":"URL Restriction Bypass in plantuml/plantuml"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"plantuml/plantuml","version":{"version_data":[{"version_affected":"<","version_value":"V1.2022.5"}]}}]},"vendor_name":"plantuml"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-918 Server-Side Request Forgery (SSRF)"}]}]},"references":{"reference_data":[{"name":"https://huntr.dev/bounties/0d737527-86e1-41d1-9d37-b2de36bc063a","refsource":"CONFIRM","url":"https://huntr.dev/bounties/0d737527-86e1-41d1-9d37-b2de36bc063a"},{"name":"https://github.com/plantuml/plantuml/commit/93e5964e5f35914f3f7b89de620c596795550083","refsource":"MISC","url":"https://github.com/plantuml/plantuml/commit/93e5964e5f35914f3f7b89de620c596795550083"},{"refsource":"FEDORA","name":"FEDORA-2022-e6c09a89eb","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHUE4G5CAJUD7L2QPJF6U4JYQTP7CNNL/"},{"refsource":"FEDORA","name":"FEDORA-2022-fda9f1f7bd","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J4DP36G2VBOZUNQIUZ5LVJKZIVO4SDAI/"}]},"source":{"advisory":"0d737527-86e1-41d1-9d37-b2de36bc063a","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-05-14 10:15:00","lastModifiedDate":"2023-11-07 03:41:00","problem_types":["CWE-918"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:plantuml:plantuml:*:*:*:*:*:*:*:*","versionEndExcluding":"1.2022.5","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}