CVE-2023-3398

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 26, 2023
Updated: Jun 30, 2023
CWE ID 400

Summary

CVE-2023-3398 identifies a Denial of Service (DoS) vulnerability in the jgraph/drawio GitHub repository before version 18.1.3. Maliciously crafted files can trigger the DoS condition, leading to resource exhaustion and potential unavailability of affected instances. Attackers may exploit this vulnerability by supplying specially crafted input files, causing the application to crash or become unresponsive, potentially disrupting critical workflows. This issue underscores the importance of keeping software up to date to mitigate potential security risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share