Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr3q-pqgq-m8c2

Опубликовано: 12 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Spoofing attack in swagger-ui

Swagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions.

Пакеты

Наименование

swagger-ui

npm
Затронутые версииВерсия исправления

< 4.1.3

4.1.3

Наименование

org.webjars:swagger-ui

maven
Затронутые версииВерсия исправления

< 4.1.3

4.1.3

EPSS

Процентиль: 99%
0.83676
Высокий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-918
CWE-922

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 4 года назад

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

CVSS3: 4.3
nvd
почти 4 года назад

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

CVSS3: 4.3
debian
почти 4 года назад

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct ...

EPSS

Процентиль: 99%
0.83676
Высокий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-918
CWE-922