Описание
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that @import within the JSON data was a functional attack method.
Ссылки
- Release Notes
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI b ...
Уязвимость компонента Cascading Style Sheets (CSS) инструмента для создания интерактивной документации Swagger UI, позволяющая нарушителю осуществить межсайтовую сценарную атаку
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2