CVE-2023-3398: Denial of Service in jgraph/drawio
Published Jun 26, 2023
·Updated
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.
Affected Software
1 affected component
Diagrams Drawio<18.1.3
Remediation
Event History
Jun 26, 2023
CVE Published
via MITRE·10:05 AM
Data Sourced
via MITRE·10:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3398.
2
What is the severity of CVE-2023-3398?
The severity of CVE-2023-3398 is high with a severity value of 7.5.
3
What is affected by CVE-2023-3398?
The GitHub repository jgraph/drawio prior to version 18.1.3 is affected by CVE-2023-3398.
4
What is the fix for CVE-2023-3398?
Update the affected software to version 18.1.3 or higher.
5
Where can I find more information about CVE-2023-3398?
You can find more information about CVE-2023-3398 in the references provided: [GitHub Commit](https://github.com/jgraph/drawio/commit/064729fec4262f9373d9fdcafda0be47cd18dd50) and [Huntr Bounty](https://huntr.dev/bounties/aa087215-80e1-433d-b870-650705630e69).