CVE-2022-1231: XSS via Embedded SVG in SVG Diagram Format in plantuml/plantuml
Last updated 18 March 2025
Other sources
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1231?
CVE-2022-1231 has a high severity due to the potential for stored XSS attacks that can lead to account hijacking and code execution.
How do I fix CVE-2022-1231?
To fix CVE-2022-1231, upgrade PlantUML to version 1.2022.4 or later.
Which versions of PlantUML are affected by CVE-2022-1231?
CVE-2022-1231 affects PlantUML versions prior to 1.2022.4.
What types of attacks can be executed due to CVE-2022-1231?
CVE-2022-1231 can lead to attacks such as secret stealing, account hijacking, or even remote code execution.
Is CVE-2022-1231 specific to any operating systems?
Yes, CVE-2022-1231 specifically affects Fedora 35 and 36 when using PlantUML.