Логотип exploitDog
bind:CVE-2017-1000208
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-1000208

Количество 2

Количество 2

nvd логотип

CVE-2017-1000208

около 8 лет назад

A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-q7pf-qr96-2vq5

больше 7 лет назад

Deserialization of Untrusted Data in swagger-parser

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-1000208

A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.

CVSS3: 8.8
0%
Низкий
около 8 лет назад
github логотип
GHSA-q7pf-qr96-2vq5

Deserialization of Untrusted Data in swagger-parser

CVSS3: 8.8
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу