Логотип exploitDog
bind:CVE-2018-25031
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-25031

Количество 4

Количество 4

ubuntu логотип

CVE-2018-25031

почти 4 года назад

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

CVSS3: 4.3
EPSS: Высокий
nvd логотип

CVE-2018-25031

почти 4 года назад

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

CVSS3: 4.3
EPSS: Высокий
debian логотип

CVE-2018-25031

почти 4 года назад

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct ...

CVSS3: 4.3
EPSS: Высокий
github логотип

GHSA-cr3q-pqgq-m8c2

почти 4 года назад

Spoofing attack in swagger-ui

CVSS3: 4.3
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-25031

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

CVSS3: 4.3
84%
Высокий
почти 4 года назад
nvd логотип
CVE-2018-25031

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

CVSS3: 4.3
84%
Высокий
почти 4 года назад
debian логотип
CVE-2018-25031

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct ...

CVSS3: 4.3
84%
Высокий
почти 4 года назад
github логотип
GHSA-cr3q-pqgq-m8c2

Spoofing attack in swagger-ui

CVSS3: 4.3
84%
Высокий
почти 4 года назад

Уязвимостей на страницу