MEDIUM4.3
GHSA-cr3q-pqgq-m8c2
Spoofing attack in swagger-ui
Quick fix
GHSA-cr3q-pqgq-m8c2 — swagger-ui: upgrade to the fixed version with the command below.
npm install swagger-ui@4.1.3Details
Swagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars:swagger-ui
Introduced in:
0Fixed in: 4.1.3Fix
# pom.xml: bump <version>4.1.3</version> for org.webjars:swagger-uiReferences
- https://nvd.nist.gov/vuln/detail/CVE-2018-25031[ADVISORY]
- https://github.com/swagger-api/swagger-ui/issues/4872[WEB]
- https://github.com/swagger-api/swagger-ui/pull/7697[WEB]
- https://github.com/swagger-api/swagger-ui[PACKAGE]
- https://github.com/swagger-api/swagger-ui/releases/tag/v4.1.3[WEB]
- https://security.netapp.com/advisory/ntap-20220407-0004[WEB]
- https://security.snyk.io/vuln/SNYK-JS-SWAGGERUI-2314885[WEB]