github.com
https://github.com/jgraph/drawio/commit/283d41ec80ad410d68634245cf56114bc19331ee CVE-2022-1713
HIGHNuclei
SSRF on /proxy in jgraph/drawio
Record summary
CVE-2022-1713 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jgraph/drawioBrowse jgraph / jgraph/drawio | CVE List | Before 18.0.4 | affected |
Nuclei templates
1ProjectDiscoveryHIGHDrawio <18.0.4 - Server-Side Request ForgeryCVSS 7.5
Drawio prior to 18.0.4 is vulnerable to server-side request forgery. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.
Impact
Successful exploitation of this vulnerability could result in unauthorized access to sensitive internal resources and potential data leakage.
Remediation
Upgrade Drawio to version 18.0.4 or later to mitigate the SSRF vulnerability.
WeaknessesCWE-918
Authorspikpikcu
Template tagscvecve2022drawiossrfosshuntrdiagramsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:diagrams:drawio:*:*:*:*:*:*:*:*
Shodan: http.title:"Flowchart Maker"
Shodan: http.title:"flowchart maker"
FOFA: title="flowchart maker"
Google: intitle:"flowchart maker"
https://huntr.dev/bounties/cad3902f-3afb-4ed2-abd0-9f96a248de11 https://github.com/jgraph/drawio/commit/283d41ec80ad410d68634245cf56114bc19331ee https://nvd.nist.gov/vuln/detail/CVE-2022-1713 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3huntr.devConfirmation
https://huntr.dev/bounties/cad3902f-3afb-4ed2-abd0-9f96a248de11 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1713