VDB
Sign up
MEDIUM4.3

GHSA-cr3q-pqgq-m8c2

Spoofing attack in swagger-ui

Quick fix

GHSA-cr3q-pqgq-m8c2 — swagger-ui: upgrade to the fixed version with the command below.

npm install swagger-ui@4.1.3

Details

Swagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/swagger-ui
Introduced in: 0Fixed in: 4.1.3
Fixnpm install swagger-ui@4.1.3
Maven/org.webjars:swagger-ui
Introduced in: 0Fixed in: 4.1.3
Fix# pom.xml: bump <version>4.1.3</version> for org.webjars:swagger-ui

References