github.com
https://github.com/jgraph/drawio/commit/8f3f95a05b701175b639ba9572dc4e0fb7c46b02 CVE-2022-3133
HIGH
OS Command Injection in jgraph/drawio
Record summary
CVE-2022-3133 has a selected CVSS score of 7.8 (high).
Description
OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jgraph/drawioBrowse jgraph / jgraph/drawio | CVE List | Before 20.3.0 | affected |
References
3huntr.devConfirmation
https://huntr.dev/bounties/2d93052f-efc6-4647-9a6d-8b08dc251223 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-3133