CVE-2022-1723: Server-Side Request Forgery (SSRF) in jgraph/drawio
Published May 17, 2022
·Updated
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.
Affected Software
1 affected component
Diagrams Drawio<18.0.6
Remediation
Event History
May 17, 2022
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1723?
CVE-2022-1723 has been classified as a high-severity Server-Side Request Forgery (SSRF) vulnerability.
2
How do I fix CVE-2022-1723?
To fix CVE-2022-1723, upgrade your Draw.io software to version 18.0.6 or later.
3
What versions of Draw.io are affected by CVE-2022-1723?
CVE-2022-1723 affects all versions of Draw.io prior to version 18.0.6.
4
What is Server-Side Request Forgery in the context of CVE-2022-1723?
Server-Side Request Forgery in CVE-2022-1723 allows an attacker to make unauthorized requests from the vulnerable server, potentially leading to data exposure.
5
Is there a workaround for CVE-2022-1723 if I cannot update immediately?
While it is highly advised to update, if immediate updating is not possible, limiting network access and not exposing the application to untrusted networks may help reduce risk.