CVE-2023-3975: OS Command Injection in jgraph/drawio
Published Jul 27, 2023
·Updated
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
Affected Software
1 affected component
Diagrams Drawio<21.5.0
Remediation
Event History
Jul 27, 2023
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-3975.
2
What is the severity of CVE-2023-3975?
The severity of CVE-2023-3975 is critical (9.8).
3
What is the affected software for CVE-2023-3975?
The affected software for CVE-2023-3975 is the GitHub repository jgraph/drawio prior to version 21.5.0.
4
How can I fix CVE-2023-3975?
To fix CVE-2023-3975, update the affected software to version 21.5.0 or later.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-3975?
The CWE for CVE-2023-3975 is CWE-77 and CWE-78.