github.com
https://github.com/jgraph/drawio/commit/7a68ebe22a64fe722704e9c4527791209fee2034 CVE-2022-1723
HIGH
Server-Side Request Forgery (SSRF) in jgraph/drawio
Record summary
CVE-2022-1723 has a selected CVSS score of 7.5 (high).
Description
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jgraph/drawioBrowse jgraph / jgraph/drawio | CVE List | Before 18.0.6 | affected |
References
3huntr.devConfirmation
https://huntr.dev/bounties/619851a4-2a08-4196-80e9-ab41953491d8 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1723