PT-2022-14073 · Drawio · Drawio

Published

2022-05-16

·

Updated

2023-02-16

·

CVE-2022-1722

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions drawio versions prior to 18.0.5
Description The issue is related to a Server-Side Request Forgery (SSRF) in the editor's proxy via an IPv6 link-local address. This allows for SSRF to internal link-local IPv6 addresses.
Recommendations For versions prior to 18.0.5, update to version 18.0.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the editor's proxy to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-1722

Affected Products

Drawio