net.sourceforge.plantuml:plantuml@1.2022.2 vulnerabilities

  • latest version

    1.2025.2

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the net.sourceforge.plantuml:plantuml package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Access Restriction Bypass

    Affected versions of this package are vulnerable to Access Restriction Bypass that allows attackers to read files on the server using %load_json, when ALLOW_PLANTUML_INCLUDE=false is set (the default).

    How to fix Access Restriction Bypass?

    Upgrade net.sourceforge.plantuml:plantuml to version 1.2023.9 or higher.

    [,1.2023.9)
    • H
    Server-side Request Forgery (SSRF)

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) by including non alphanumeric characters in a PATTERN_USERINFO value, which can bypass the allowlist when PLANTUML_SECURITY_PROFILE=ALLOWLIST is set.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade net.sourceforge.plantuml:plantuml to version 1.2023.9 or higher.

    [,1.2023.9)