github.com
https://github.com/jgraph/drawio/commit/3d3f819d7a04da7d53b37cc0ca4269c157ba2825 CVE-2022-2014
MEDIUM
Code Injection in jgraph/drawio
Record summary
CVE-2022-2014 has a selected CVSS score of 5.4 (medium).
Description
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jgraph/drawioBrowse jgraph / jgraph/drawio | CVE List | Before 19.0.2 | affected |
References
3huntr.devConfirmation
https://huntr.dev/bounties/911a4ada-7fd6-467a-a464-b88604b16ffc nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-2014