CVE-2022-2014: Code Injection in jgraph/drawio
Published Jun 8, 2022
·Updated
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
Affected Software
1 affected component
Diagrams Drawio<19.0.2
Remediation
Event History
Jun 8, 2022
CVE Published
via MITRE·07:25 AM
Data Sourced
via MITRE·07:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2014?
The severity of CVE-2022-2014 is critical, with a severity value of 5.4.
2
How does CVE-2022-2014 affect the affected software?
CVE-2022-2014 affects the Drawio software with versions up to exclusive 19.0.2.
3
What is the Common Weakness Enumeration (CWE) of CVE-2022-2014?
The CWE of CVE-2022-2014 is CWE-94 (Improper Control of Generation of Code).
4
Is there a fix available for CVE-2022-2014?
Yes, a fix for CVE-2022-2014 is available in version 19.0.2 and later of the Drawio software.
5
Where can I find more information about CVE-2022-2014?
You can find more information about CVE-2022-2014 in the references provided: [1](https://github.com/jgraph/drawio/commit/3d3f819d7a04da7d53b37cc0ca4269c157ba2825), [2](https://huntr.dev/bounties/911a4ada-7fd6-467a-a464-b88604b16ffc).