CRITICAL
GHSA-p239-93f7-h6xf
Cross-Site Scripting in swagger-ui
Quick fix
GHSA-p239-93f7-h6xf — swagger-ui: upgrade to the fixed version with the command below.
npm install swagger-ui@2.2.1Details
Affected versions of `swagger-ui` contain a cross-site scripting vulnerability in the key names of a specific nested object in the JSON document.
## Proof of Concept The vulnerable object structure is: ``` { "definitions": { "arbitraryVal": { "properties": { "<INJECTABLE_KEY_NAME>": "LoremIpsum" } } } } ``` Malicious JSON documents can be loaded in by providing a URL to them in the `url` query string parameter.
## Recommendation
Update to version 2.2.1 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-5682[ADVISORY]
- https://github.com/swagger-api/swagger-ui/issues/1865[WEB]
- https://community.rapid7.com/community/infosec/blog/2016/09/02/r7-2016-19-persistent-xss-via-unescaped-parameters-in-swagger-ui[WEB]
- https://github.com/swagger-api/swagger-ui[PACKAGE]
- https://www.npmjs.com/advisories/126[WEB]