CVE-2022-1721: Path Traversal in WellKnownServlet in jgraph/drawio
Published May 16, 2022
·Updated
Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application.
Affected Software
1 affected component
Diagrams Drawio<18.0.5
Remediation
Event History
May 16, 2022
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1721?
The severity of CVE-2022-1721 is high with a CVSS score of 7.5.
2
How can I fix the Path Traversal vulnerability in WellKnownServlet in GitHub repository jgraph/drawio?
To fix the Path Traversal vulnerability in WellKnownServlet in GitHub repository jgraph/drawio, update the software to version 18.0.5 or newer.
3
What software is affected by CVE-2022-1721?
The affected software is Diagrams Drawio version up to but excluding 18.0.5.