VDB
Sign up
MEDIUM6.1

GHSA-6c9x-mj3g-h47x

Spoofing attack in swagger-ui-dist

Quick fix

GHSA-6c9x-mj3g-h47x — swagger-ui-dist: upgrade to the fixed version with the command below.

npm install swagger-ui-dist@4.1.3

Details

The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/swagger-ui-dist
Introduced in: 0Fixed in: 4.1.3
Fixnpm install swagger-ui-dist@4.1.3

References