CVE-2022-1784: Server-Side Request Forgery (SSRF) in jgraph/drawio
Published May 20, 2022
·Updated
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.
Affected Software
1 affected component
Diagrams Drawio<18.0.8
Remediation
Event History
May 20, 2022
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1784?
The severity of CVE-2022-1784 is high with a severity value of 7.5.
2
How does CVE-2022-1784 affect the software?
CVE-2022-1784 affects the GitHub repository jgraph/drawio prior to version 18.0.8.
3
What is Server-Side Request Forgery (SSRF)?
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to send malicious requests from the server to other internal or external resources.
4
How can I fix CVE-2022-1784?
To fix CVE-2022-1784, update the jgraph/drawio software to version 18.0.8 or later.
5
Where can I find more information about CVE-2022-1784?
You can find more information about CVE-2022-1784 at the following references: [GitHub Commit](https://github.com/jgraph/drawio/commit/c63f3a04450f30798df47f9badbc74eb8a69fbdf), [Huntr Bounty](https://huntr.dev/bounties/d1330ce8-cccb-4bae-b9a9-a03b97f444a5).