S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1713 Scanner

CVE-2022-1713 scanner - Server-Side Request Forgery (SSRF) vulnerability in jgraph/drawio

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1713
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
jgraph/drawioby jgraph
AFFECTED< 18.0.4SAFE ✓≥ 18.0.4
Updated Aug 22, 2026View on NVD →
Detail

Jgraph/drawio is a software tool that allows users to create, edit, and share diagrams and flowcharts effortlessly. It is often used by businesses, educational institutions, and individuals as a visual aid for brainstorming, planning, and organizing data. The software is highly customizable and offers a wide range of features, including a drag-and-drop interface, a repository of pre-made templates, and real-time collaboration capabilities.

However, this product contains a significant vulnerability that has been identified as CVE-2022-1713. This vulnerability enables an attacker to exploit a Server-Side Request Forgery (SSRF) vulnerability on /proxy in a GitHub repository, leading to a potential leak of sensitive information. An attacker can make a request acting as the server and can read its contents without authorization.

This vulnerability can leave users' digital assets open to exploitation, leading to confidential data leaks and possible financial losses for businesses and organizations. Attackers can use the information obtained from this vulnerability to gain unauthorized access and steal valuable data, disrupt business operations or even spread malware.

In conclusion, it is crucial to stay informed about potential vulnerabilities in your digital assets and take the necessary precautions to protect them. With the pro features of s4e.io, readers can easily and quickly learn about vulnerabilities in their digital assets, making it easier to stay ahead of threats and protect their valuable data. It is crucial to be proactive in managing potential risks to prevent cyberattacks and data breaches.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to update their software to the latest version of jgraph/drawio. Additionally, recommended precautions include:

  • Limiting or restricting access to the software
  • Implementing server-side input validation
  • Applying HTTP restrictions based on a whitelist
  • Employing security measures to prevent unauthorized access

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.