We found results for “”
CVE-2024-22207
Good to know:
Date: January 15, 2024
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of "@fastify/swagger-ui" without "baseDir" set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the "baseDir" option can also work around this vulnerability.
Language: JS
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Initialization of a Resource with an Insecure Default
CWE-1188Top Fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


