CVE-2022-1713: SSRF on /proxy in jgraph/drawio
Published May 16, 2022
·Updated
SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.
Affected Software
1 affected component
Diagrams Drawio<18.0.4
Remediation
Event History
May 16, 2022
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1713?
CVE-2022-1713 is classified as a high severity vulnerability due to its potential for sensitive information leakage.
2
How do I fix CVE-2022-1713?
To fix CVE-2022-1713, upgrade to version 18.0.4 or later of the Draw.io software.
3
What type of vulnerability is CVE-2022-1713?
CVE-2022-1713 is a Server-Side Request Forgery (SSRF) vulnerability.
4
What can an attacker do with CVE-2022-1713?
An attacker can exploit CVE-2022-1713 to make requests as the server and potentially read sensitive content.
5
Which versions of Draw.io are affected by CVE-2022-1713?
Versions of Draw.io prior to 18.0.4 are affected by CVE-2022-1713.