Bug 2076162 (CVE-2022-1231) - CVE-2022-1231 plantuml: Stored XSS in the context of the diagram embedder
Summary: CVE-2022-1231 plantuml: Stored XSS in the context of the diagram embedder
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2022-1231
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2076163
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-04-18 06:02 UTC by Sandipan Roy
Modified: 2022-04-18 08:56 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2022-04-18 08:56:56 UTC
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2022-04-18 06:02:19 UTC
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).

https://github.com/plantuml/plantuml/commit/c9137be051ce98b3e3e27f65f54ec7d9f8886903
https://huntr.dev/bounties/27db9509-6cd3-4148-8d70-5942f3837604

Comment 1 Sandipan Roy 2022-04-18 06:02:38 UTC
Created plantuml tracking bugs for this issue:

Affects: fedora-all [bug 2076163]

Comment 2 Product Security DevOps Team 2022-04-18 08:56:54 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.