
We found results for “”
WS-2017-0143
Good to know:


Date: September 1, 2016
Affected versions of the package are vulnerable to Cross-site Scripting (XSS) due to not escaping html script tags.
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version dhawton/l5-swagger-redoc - 4.0.1;dhawton/l5-swagger-redoc - v2.0;dhawton/l5-swagger-redoc - 3.0.1;jessekoska/swagger-lume - v2.0.24;smskin/l5-swagger - 5.0;dennis1804/iq-swagger - no_fix;dennis1804/iq-swagger - dev-dependabot/composer/illuminate/support-approx-8.16;sergeyfast/eazy-jsonrpc - no_fix;sergeyfast/eazy-jsonrpc - v1.0;laminas-api-tools/api-tools-documentation-swagger - 1.3.0;ramzyvirani/laravel-boilerplate - no_fix;ramzyvirani/laravel-boilerplate - dev-snyk-fix-ad10bb3d08f682b4190aefeb23a5c3d5;ramzyvirani/laravel-boilerplate - dev-snyk-fix-6118335e7ee4db4dc6929725f8b9be70;folksyfolks/l5-swagger - dev-upgrade-to-swagger-ui-4;folksyfolks/l5-swagger - 2.1;folksyfolks/l5-swagger - 3.1.4;zfcampus/zf-apigility-documentation-swagger - dev-master;zfcampus/zf-apigility-documentation-swagger - 1.3.0;ci-blox/ignition-go - 1.0.0-beta.1;ci-blox/ignition-go - no_fix;imikemiller/l5-swagger-redoc - 3.0.1;imikemiller/l5-swagger-redoc - 4.0.1;imikemiller/l5-swagger-redoc - v2.0;rich2k/l5-swagger - 5.0;visiosoft/l5-swagger - 3.x-dev;damian-nz/l5-swagger - 3.2;damian-nz/l5-swagger - dev-master;activelamp/swagger-ui-bundle - dev-nelmio_integration;riverslei/laravel-swagger - no_fix;ServiceStack.Api.Swagger - 4.0.8;ServiceStack.Api.Swagger - 4.0.35;ServiceStack.Api.Swagger - 4.5.12;libgraviton/swagger-ui - v1.0;alexmaramaldo/swaggervel-2 - no_fix;mreko/l5-swagger - 4.0.1;mreko/l5-swagger - 3.0.1;mreko/l5-swagger - v2.0;dreamfactory/df-swagger-ui - no_fix;dreamfactory/df-swagger-ui - 0.4.0;dreamfactory/df-swagger-ui - v2.2.3;ernestoponce/slimproject - no_fix;kbrabrand/silex-swagger-ui - no_fix;mymdz/l5-swagger - 5.0;raftx24/l5-swagger - v2.0;raftx24/l5-swagger - 3.0.1;raftx24/l5-swagger - 4.0.1;dolibarr/dolibarr - 9.0.0;NServiceKit.Api.Swagger - no_fix;luracast/restler - 1.0.20;luracast/restler - 4.0.0;luracast/restler - 2.2.0;luracast/restler - 5.07;luracast/restler - 5.0.6;kubotak-is/l5-swagger - 4.0.1;kubotak-is/l5-swagger - 3.0.1;kubotak-is/l5-swagger - v2.0;swagger-ui - 2.0.3;swagger-ui - 2.2.3;juzaweb/l5-swagger - 5.0;cr3a7ure/core - no_fix;cr3a7ure/core - dev-docminor;digitalunited/wp-elastic-api - v0.1;digitalunited/wp-elastic-api - v0.1.4;digitalunited/wp-elastic-api - v0.1.3;digitalunited/wp-elastic-api - v0.1.2;fmarmo/swagger-lume - 2.0;luoxiaojun1992/sf - v1.0.0;jinsoft/laravel-swagger - no_fix;hadeswang/jlapp-swaggervel - 1.0.x-dev;ServiceStack.Api.Swagger.Signed - 4.5.12;ServiceStack.Api.Swagger.Signed - 4.0.35;latrell/swagger - 1.0.2;pmvc-app/swagger_ui - no_fix;dandisy/webcore-base - 1.0.0;dandisy/webcore-base - no_fix;keeko/developer-app - v0.2;darkaonline/l5-swagger - 3.0.1;darkaonline/l5-swagger - v2.0;darkaonline/l5-swagger - dev-upgrade-to-swagger-ui-4;firdaushatta/l5-swagger - dev-upgrade-to-swagger-ui-4;firdaushatta/l5-swagger - 5.0;firdaushatta/l5-swagger - dev-firdaushatta-patch-2;firdaushatta/l5-swagger - dev-firdaushatta-patch-1;helingfeng/l5-swagger - 5.0;vsmoraes/swagger-ui-bundle - no_fix;vsmoraes/swagger-ui-bundle - dev-nelmio_integration;bluzphp/skeleton - 2.0.2;rodchyn/api-platform-core - v2.0.0-rc.1;pharmit/swaggervel - 1.0.x-dev;pleio/pleio_rest - no_fix;dreamfactory/df-api-docs-ui - 1.1.0;govtnz/swagger-ui - v1.0;OpenRastaSwagger - 1.0.3.21;kizi/easyminer-easyminercenter - no_fix;kizi/easyminer-easyminercenter - v2.0;restler/framework - 4.0.0;restler/framework - 3.0.0-RC1;restler/framework - 5.07;restler/framework - 5.0.6;mahmoodbabaei/etribes-code-challenge - no_fix;gajendrajain20/laravel-pioneer-cms - no_fix;open-resource-manager/core - no_fix;dreamfactory/app-admin - 1.0.4;dreamfactory/app-admin - no_fix;sjje/swaggervel - dev-master;jjdoor/swagger-lume - 2.0;vjeantet/silex-simple-rest-swagger - no_fix;vSwashbuckle.Core - 1.0.1;dandisy/laravel-generator - dev-dependabot/npm_and_yarn/templates/vuejs/js/eslint-4.19.1;dandisy/laravel-generator - 1.2.7;dandisy/laravel-generator - 1.0.0;hasangilak/l5-swagger - 5.0;dandisy/webcore - 1.0.0;dandisy/webcore - 1.0.6;dandisy/webcore - no_fix;hos/hos-framework - no_fix;iwanli/laravel5-swagger - no_fix;steamuloabeaujou/api-platform - v2.0.0-rc.1;fxmonster/l5-swagger - 5.0;davigs/swagger-lume - 2.0;imjarek/laravel-swagger - 5.0;yaangvu/swagger-lume - 2.0;JYM.IdentityServer.Swagger - no_fix;Odn.Swagger.Net - no_fix;api-platform/core - v2.0.0-rc.1;jlapp/swaggervel - 1.0.x-dev;swagger-api/swagger-ui - v2.2.3;dandisy/adminlte-templates - 1.2.2;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.webjars.npm:swagger-tools:0.9.16;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.1;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.webjars.npm:swagger-ui-cimpress:no_fix;io.fabric8.quickstarts.cxf.jaxrs:spring-boot-cxf-jaxrs-xml:no_fix;org.webjars:swagger-ui:2.2.5;org.webjars.npm:github-com-jensoleg-swagger-ui:no_fix;org.webjars.npm:swagger-ui:2.2.8
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |