CVE-2022-1767: Server-Side Request Forgery (SSRF) in jgraph/drawio
Published May 18, 2022
·Updated
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.
Affected Software
1 affected component
Diagrams Drawio<18.0.7
Remediation
Event History
May 18, 2022
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1767?
CVE-2022-1767 has been classified with a moderate severity level due to the potential for Server-Side Request Forgery (SSRF).
2
How do I fix CVE-2022-1767?
To fix CVE-2022-1767, upgrade to version 18.0.7 or later of the Draw.io application.
3
What types of attacks can CVE-2022-1767 enable?
CVE-2022-1767 can enable attackers to perform Server-Side Request Forgery (SSRF) attacks, potentially accessing internal resources.
4
Which versions of Draw.io are affected by CVE-2022-1767?
CVE-2022-1767 affects all versions of Draw.io prior to version 18.0.7.
5
Is there a workaround for CVE-2022-1767 before upgrading?
There is no specific workaround for CVE-2022-1767, so upgrading to the patched version is recommended.