CVE-2022-1711: Server-Side Request Forgery (SSRF) in jgraph/drawio
Published May 17, 2022
·Updated
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.
Affected Software
1 affected component
Diagrams Drawio<18.0.5
Remediation
Event History
May 17, 2022
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1711?
CVE-2022-1711 has been classified as a medium severity vulnerability due to its potential for Server-Side Request Forgery attacks.
2
How do I fix CVE-2022-1711?
To mitigate CVE-2022-1711, upgrade to version 18.0.5 or later of the Draw.io application.
3
What is Server-Side Request Forgery in CVE-2022-1711?
Server-Side Request Forgery in CVE-2022-1711 allows an attacker to send unauthorized requests from the server, potentially exposing sensitive information.
4
What versions are affected by CVE-2022-1711?
CVE-2022-1711 affects all versions of Draw.io prior to 18.0.5.
5
Is there a public exploit available for CVE-2022-1711?
There are no known public exploits for CVE-2022-1711 at this time.