CVE-2022-1815: Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio
Published May 25, 2022
·Updated
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
Affected Software
1 affected component
Diagrams Drawio<18.1.2
Remediation
Event History
May 25, 2022
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1815?
CVE-2022-1815 is classified as a moderate-severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2022-1815?
To fix CVE-2022-1815, update the Draw.io application to version 18.1.2 or later.
3
What type of information is exposed in CVE-2022-1815?
CVE-2022-1815 exposes sensitive information to unauthorized actors, which could include confidential data stored within the application.
4
Who is affected by CVE-2022-1815?
Users of the Draw.io application versions prior to 18.1.2 are affected by CVE-2022-1815.
5
When was CVE-2022-1815 disclosed?
CVE-2022-1815 was disclosed in 2022, specifically affecting versions of the software before the release of 18.1.2.