VDB
Sign up
MEDIUM5.3

GHSA-62jr-84gf-wmg4

Default swagger-ui configuration exposes all files in the module

Quick fix

GHSA-62jr-84gf-wmg4 — @fastify/swagger-ui: upgrade to the fixed version with the command below.

npm install @fastify/swagger-ui@2.1.0

Details

### Impact

The default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module.

### Patches

Update to v2.1.0

### Workarounds

Use the `baseDir` option

### References

[HackerOne report ](https://hackerone.com/reports/2312369).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@fastify/swagger-ui
Introduced in: 2.0.0Fixed in: 2.1.0
Fixnpm install @fastify/swagger-ui@2.1.0

References