jgraph Vulnerabilities and Affected Products
Vulnerabilities associated with jgraph/drawio.
Products
Clear product- jgraph/drawio26 vulnerabilities
- drawio5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-3975CRITICAL | OS Command Injection in jgraph/drawioOS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0. CWE-78Jul 27, 2023 | CVSS9.8v3.1 | EPSS2.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3974CRITICAL | OS Command Injection in jgraph/drawioOS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0. CWE-78Jul 27, 2023 | CVSS9.8v3.1 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3973MEDIUM | Cross-site Scripting (XSS) - Reflected in jgraph/drawioCross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3. CWE-79Jul 27, 2023 | CVSS6.1v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3398HIGH | Denial of Service in jgraph/drawioDenial of Service in GitHub repository jgraph/drawio prior to 18.1.3. CWE-400Jun 26, 2023 | CVSS7.5v3.1 | EPSS0.969% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3026MEDIUM | Cross-site Scripting (XSS) - Stored in jgraph/drawioCross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8. CWE-79Jun 1, 2023 | CVSS6.1v3.1 | EPSS0.534% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3873MEDIUM | Cross-site Scripting (XSS) - DOM in jgraph/drawioCross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2. CWE-79Nov 7, 2022 | CVSS6.1v3.1 | EPSS0.624% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3223MEDIUM | Cross-site Scripting (XSS) - Stored in jgraph/drawioCross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1. CWE-79Sep 16, 2022 | CVSS6.1v3.1 | EPSS0.634% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3133HIGH | OS Command Injection in jgraph/drawioOS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0. CWE-78Sep 9, 2022 | CVSS7.8v3.1 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3138MEDIUM | Cross-site Scripting (XSS) - Generic in jgraph/drawioCross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. CWE-79Sep 8, 2022 | CVSS6.1v3.1 | EPSS0.538% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3148MEDIUM | Cross-site Scripting (XSS) - Generic in jgraph/drawioCross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. CWE-79Sep 8, 2022 | CVSS6.1v3.1 | EPSS0.538% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3127MEDIUM | Cross-site Scripting (XSS) - Stored in jgraph/drawioCross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8. CWE-79Sep 5, 2022 | CVSS5.4v3.1 | EPSS0.543% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3065HIGH | Improper Access Control in jgraph/drawioImproper Access Control in GitHub repository jgraph/drawio prior to 20.2.8. CWE-284Sep 2, 2022 | CVSS7.5v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2015MEDIUM | Cross-site Scripting (XSS) - Stored in jgraph/drawioCross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2. CWE-79Jun 8, 2022 | CVSS5.4v3.1 | EPSS0.621% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2014MEDIUM | Code Injection in jgraph/drawioCode Injection in GitHub repository jgraph/drawio prior to 19.0.2. CWE-94Jun 8, 2022 | CVSS5.4v3.1 | EPSS0.713% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1815HIGH | Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawioExposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. | CVSS7.5v3.1 | EPSS6.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-1784HIGH | Server-Side Request Forgery (SSRF) in jgraph/drawioServer-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8. CWE-918May 20, 2022 | CVSS7.5v3.1 | EPSS1.76% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1730MEDIUM | Cross-site Scripting (XSS) - Stored in jgraph/drawioCross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. CWE-79May 19, 2022 | CVSS4.6v3.1 | EPSS0.609% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1774MEDIUM | Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawioExposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. | CVSS6.1v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1767HIGH | Server-Side Request Forgery (SSRF) in jgraph/drawioServer-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7. CWE-918May 18, 2022 | CVSS7.5v3.1 | EPSS1.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1727HIGH | Improper Input Validation in jgraph/drawioImproper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6. CWE-20May 18, 2022 | CVSS8.8v3.1 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1711HIGH | Server-Side Request Forgery (SSRF) in jgraph/drawioServer-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5. | CVSS7.5v3.1 | EPSS5.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-1723HIGH | Server-Side Request Forgery (SSRF) in jgraph/drawioServer-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6. CWE-918May 17, 2022 | CVSS7.5v3.1 | EPSS1.71% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1713HIGH | SSRF on /proxy in jgraph/drawioSSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information. | CVSS7.5v3.1 | EPSS9.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-1721HIGH | Path Traversal in WellKnownServlet in jgraph/drawioPath Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application. CWE-22May 16, 2022 | CVSS7.5v3.1 | EPSS2.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
SSRF in editor's proxy via IPv6 link-local address in jgraph/drawioSSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses CWE-918May 16, 2022 | CVSS3.3v3.1 | EPSS0.541% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |