MEDIUM5.3
GHSA-62jr-84gf-wmg4
Default swagger-ui configuration exposes all files in the module
Quick fix
GHSA-62jr-84gf-wmg4 — @fastify/swagger-ui: upgrade to the fixed version with the command below.
npm install @fastify/swagger-ui@2.1.0Details
### Impact
The default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module.
### Patches
Update to v2.1.0
### Workarounds
Use the `baseDir` option
### References
[HackerOne report ](https://hackerone.com/reports/2312369).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/fastify/fastify-swagger-ui/security/advisories/GHSA-62jr-84gf-wmg4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-22207[ADVISORY]
- https://github.com/fastify/fastify-swagger-ui/commit/13d799a2c5f14d3dd5b15892e03bbcbae63ee6f7[WEB]
- https://github.com/fastify/fastify-swagger-ui[PACKAGE]
- https://security.netapp.com/advisory/ntap-20240216-0002[WEB]