漏洞描述
Drawio before 18.1.2 is susceptible to server-side request forgery via the /service endpoint in jgraph/drawio. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
huntr.devhttps://huntr.dev/bounties/6e856a25-9117-47c6-9375-52f78876902f/↗huntr.devhttps://huntr.dev/bounties/6e856a25-9117-47c6-9375-52f78876902f↗github.comhttps://github.com/jgraph/drawio/commit/c287bef9101d024b1fd59d55ecd530f25000f9d8↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-1815↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗