Количество 4
Количество 4
CVE-2019-17495
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.
CVE-2019-17495
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI b ...
GHSA-c427-hjc3-wrfw
Cross-site scripting in Swagger-UI
BDU:2020-05182
Уязвимость компонента Cascading Style Sheets (CSS) инструмента для создания интерактивной документации Swagger UI, позволяющая нарушителю осуществить межсайтовую сценарную атаку
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-17495 A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method. | CVSS3: 9.8 | 12% Средний | больше 6 лет назад | |
CVE-2019-17495 A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI b ... | CVSS3: 9.8 | 12% Средний | больше 6 лет назад | |
GHSA-c427-hjc3-wrfw Cross-site scripting in Swagger-UI | CVSS3: 9.8 | 12% Средний | больше 6 лет назад | |
BDU:2020-05182 Уязвимость компонента Cascading Style Sheets (CSS) инструмента для создания интерактивной документации Swagger UI, позволяющая нарушителю осуществить межсайтовую сценарную атаку | CVSS3: 9.8 | 12% Средний | больше 6 лет назад |
Уязвимостей на страницу