URL Restriction Bypass in plantuml/plantuml
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 1.6%
exploitation probability
1.6%top 25% of all CVEs
observed exploitation
nono source reports it
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected products
plantuml · plantuml/plantumlReferences
https://github.com/plantuml/plantuml/commit/93e5964e5f35914f3f7b89de620c596795550083https://huntr.dev/bounties/0d737527-86e1-41d1-9d37-b2de36bc063ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHUE4G5CAJUD7L2QPJF6U4JYQTP7CNNL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4DP36G2VBOZUNQIUZ5LVJKZIVO4SDAI/