CVE-2022-3133: OS Command Injection in jgraph/drawio
Published Sep 9, 2022
·Updated
OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.
Affected Software
1 affected component
Diagrams Drawio<20.3.0
Remediation
Event History
Sep 9, 2022
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3133?
The severity of CVE-2022-3133 is rated as critical due to the potential for remote code execution via OS command injection.
2
How do I fix CVE-2022-3133?
To fix CVE-2022-3133, upgrade to Draw.io version 20.3.0 or later.
3
What is the impact of CVE-2022-3133?
The impact of CVE-2022-3133 allows attackers to execute arbitrary OS commands on the vulnerable system.
4
Which versions of Draw.io are affected by CVE-2022-3133?
CVE-2022-3133 affects all versions of Draw.io prior to 20.3.0.
5
Who is affected by CVE-2022-3133?
Users and organizations using versions of Draw.io before 20.3.0 are affected by CVE-2022-3133.