CVE-2022-1722: SSRF in editor's proxy via IPv6 link-local address in jgraph/drawio
Published May 16, 2022
·Updated
SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses
Affected Software
1 affected component
Diagrams Drawio<18.0.5
Remediation
Event History
May 16, 2022
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1722?
CVE-2022-1722 is a critical vulnerability due to its potential for SSRF attacks on internal systems.
2
How do I fix CVE-2022-1722?
To fix CVE-2022-1722, upgrade Draw.io to version 18.0.5 or later.
3
What type of vulnerability is CVE-2022-1722?
CVE-2022-1722 is an SSRF vulnerability targeting internal link-local IPv6 addresses.
4
What versions of Draw.io are affected by CVE-2022-1722?
CVE-2022-1722 affects all versions of Draw.io prior to 18.0.5.
5
What can attackers achieve with CVE-2022-1722?
With CVE-2022-1722, attackers can exploit SSRF to access internal services via IPv6 link-local addresses.