icon

We found results for “

WS-2016-0044

Good to know:

icon
icon

Date: January 12, 2016

swagger-ui response headers are not escaped when generating the curl command, allowing XSS attack

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version luracast/restler - 2.2.0;luracast/restler - 5.0.6;luracast/restler - 5.07;luracast/restler - 1.0.20;luracast/restler - 4.0.0;jjdoor/swagger-lume - 2.0;fxmonster/l5-swagger - 3.x-dev;fxmonster/l5-swagger - 3.2;folksyfolks/l5-swagger - 3.1.4;hasangilak/l5-swagger - 3.2;hasangilak/l5-swagger - 3.x-dev;damian-nz/l5-swagger - 2.0.x-dev;damian-nz/l5-swagger - 3.2;damian-nz/l5-swagger - dev-master;mymdz/l5-swagger - 3.2;mymdz/l5-swagger - 3.x-dev;yaangvu/swagger-lume - 2.0;helingfeng/l5-swagger - 3.x-dev;helingfeng/l5-swagger - 3.2;firdaushatta/l5-swagger - 3.2;firdaushatta/l5-swagger - 3.x-dev;api-platform/core - v2.0.0-rc.1;visiosoft/l5-swagger - 3.x-dev;rodchyn/api-platform-core - v2.0.0-rc.1;dennis1804/iq-swagger - no_fix;dennis1804/iq-swagger - dev-dependabot/composer/illuminate/support-approx-8.16;juzaweb/l5-swagger - 3.x-dev;juzaweb/l5-swagger - 3.2;fmarmo/swagger-lume - 2.0;dolibarr/dolibarr - 9.0.0;imjarek/laravel-swagger - 3.2;imjarek/laravel-swagger - 3.x-dev;restler/framework - 5.07;restler/framework - 5.0.6;restler/framework - 4.0.0;restler/framework - 3.0.0-RC1;rich2k/l5-swagger - 3.x-dev;rich2k/l5-swagger - 3.2;smskin/l5-swagger - 3.x-dev;smskin/l5-swagger - 3.2;jessekoska/swagger-lume - v2.0.24;cr3a7ure/core - 2.1.x-dev;pleio/pleio_rest - no_fix;steamuloabeaujou/api-platform - v2.0.0-rc.1;hos/hos-framework - no_fix;swagger-ui - 2.1.5;davigs/swagger-lume - 2.0;luoxiaojun1992/sf - v1.0.0;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.webjars:swagger-ui:2.1.5;org.webjars.npm:swagger-ui:2.1.5

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us