Fedora Account System
Red Hat Associate
Red Hat Customer
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js. Upstream commit: https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3 References: https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-history https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txt
Created jgraphx tracking bugs for this issue: Affects: epel-6 [bug 1850865] Affects: fedora-all [bug 1850864]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.