GHSA-7f59-x49p-v8mq
Cross-Site Scripting in swagger-ui
Quick fix
GHSA-7f59-x49p-v8mq — swagger-ui: upgrade to the fixed version with the command below.
npm install swagger-ui@2.2.1Details
Affected versions of `swagger-ui` are vulnerable to cross-site scripting in both the `consumes` and `produces` parameters of the swagger JSON document for a given API.
Additionally, `swagger-ui` allows users to load arbitrary swagger JSON documents via the query string parameter `url`, allowing an attacker to exploit this attack against any user that the attacker can convince to visit a crafted link.
## Proof of Concept
``` http://<USER_HOSTNAME>/swagger-ui/index.html?url=http://<MALICIOUS_HOSTNAME>/malicious-swagger-file.json ````
## Recommendation
Update to version 2.2.1 or later.
Are you affected?
Enter the version of the package you're using.