github.com
https://github.com/jgraph/drawio/commit/c63f3a04450f30798df47f9badbc74eb8a69fbdf CVE-2022-1784
HIGH
Server-Side Request Forgery (SSRF) in jgraph/drawio
Record summary
CVE-2022-1784 has a selected CVSS score of 7.5 (high).
Description
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jgraph/drawioBrowse jgraph / jgraph/drawio | CVE List | Before 18.0.8 | affected |
References
3huntr.devConfirmation
https://huntr.dev/bounties/d1330ce8-cccb-4bae-b9a9-a03b97f444a5 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1784