Vulnerabilities > CVE-2022-1722 - Server-Side Request Forgery (SSRF) vulnerability in Diagrams Drawio

047910
CVSS 3.3 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
local
low complexity
diagrams
CWE-918

Summary

SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal link-local IPv6 addresses

Vulnerable Configurations

Part Description Count
Application
Diagrams
824

Common Weakness Enumeration (CWE)