Логотип exploitDog
bind:CVE-2017-1000207
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-1000207

Количество 2

Количество 2

nvd логотип

CVE-2017-1000207

около 8 лет назад

A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vgvf-9jh3-fg75

больше 7 лет назад

Deserialization of Untrusted Data in swagger-codegen

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-1000207

A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.

CVSS3: 8.8
0%
Низкий
около 8 лет назад
github логотип
GHSA-vgvf-9jh3-fg75

Deserialization of Untrusted Data in swagger-codegen

CVSS3: 8.8
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу