An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js. Upstream commit: https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3 References: https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-history https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txt
Created jgraphx tracking bugs for this issue: Affects: epel-6 [bug 1850865] Affects: fedora-all [bug 1850864]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.