We found results for “”
WS-2019-0234
Good to know:
Date: January 28, 2015
swagger-ui versions before 2.2.1 are vulnerable to XSS when allowing HTML code in the swagger.apiInfo.description value without proper sanitization, which may allow attackers to execute arbitrary JavaScript.
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Code
CWE-17Top Fix
Upgrade Version
Upgrade to version digitalunited/wp-elastic-api - v0.1.2;digitalunited/wp-elastic-api - v0.1.3;digitalunited/wp-elastic-api - v0.1.4;digitalunited/wp-elastic-api - v0.1;dandisy/webcore - no_fix;dandisy/webcore - 1.0.6;dandisy/webcore - 1.0.0;ServiceStack.Api.Swagger.Signed - 4.5.12;ServiceStack.Api.Swagger.Signed - 4.0.35;alexmaramaldo/swaggervel-2 - no_fix;raftx24/l5-swagger - 3.0.1;raftx24/l5-swagger - v2.0;raftx24/l5-swagger - 4.0.1;yaangvu/swagger-lume - 2.0;Odn.Swagger.Net - no_fix;kizi/easyminer-easyminercenter - v2.0;kizi/easyminer-easyminercenter - no_fix;imikemiller/l5-swagger-redoc - 3.0.1;imikemiller/l5-swagger-redoc - v2.0;imikemiller/l5-swagger-redoc - 4.0.1;flask-apispec - 0.7.0;flask-apispec - 0.4.0;api-platform/core - v2.0.0-rc.1;dreamfactory/app-admin - no_fix;dreamfactory/app-admin - 1.0.4;kubotak-is/l5-swagger - v2.0;kubotak-is/l5-swagger - 3.0.1;kubotak-is/l5-swagger - 4.0.1;cromwell - 0.30;rodchyn/api-platform-core - v2.0.0-rc.1;ci-blox/ignition-go - 1.0.0-beta.1;ci-blox/ignition-go - no_fix;visiosoft/l5-swagger - 3.x-dev;smskin/l5-swagger - 5.0;cr3a7ure/core - dev-docminor;cr3a7ure/core - no_fix;luracast/restler - 1.0.20;luracast/restler - 2.2.0;luracast/restler - 5.0.6;luracast/restler - 5.07;luracast/restler - 4.0.0;dennis1804/iq-swagger - dev-dependabot/composer/illuminate/support-approx-8.16;dennis1804/iq-swagger - no_fix;fmarmo/swagger-lume - 2.0;ramzyvirani/laravel-boilerplate - no_fix;ramzyvirani/laravel-boilerplate - dev-snyk-fix-ad10bb3d08f682b4190aefeb23a5c3d5;ramzyvirani/laravel-boilerplate - dev-snyk-fix-6118335e7ee4db4dc6929725f8b9be70;juzaweb/l5-swagger - 5.0;libgraviton/swagger-ui - v1.0;jinsoft/laravel-swagger - no_fix;hasangilak/l5-swagger - 5.0;sjje/swaggervel - dev-master;mreko/l5-swagger - 4.0.1;mreko/l5-swagger - v2.0;mreko/l5-swagger - 3.0.1;vSwashbuckle.Core - 1.0.1;JYM.IdentityServer.Swagger - no_fix;restler/framework - 5.07;restler/framework - 5.0.6;restler/framework - 3.0.0-RC1;restler/framework - 4.0.0;folksyfolks/l5-swagger - dev-upgrade-to-swagger-ui-4;folksyfolks/l5-swagger - 2.1;folksyfolks/l5-swagger - 3.1.4;darkaonline/l5-swagger - dev-upgrade-to-swagger-ui-4;darkaonline/l5-swagger - v2.0;darkaonline/l5-swagger - 3.0.1;ernestoponce/slimproject - no_fix;jlapp/swaggervel - 1.0.x-dev;firdaushatta/l5-swagger - dev-firdaushatta-patch-2;firdaushatta/l5-swagger - dev-firdaushatta-patch-1;firdaushatta/l5-swagger - 5.0;firdaushatta/l5-swagger - dev-upgrade-to-swagger-ui-4;sergeyfast/eazy-jsonrpc - v1.0;sergeyfast/eazy-jsonrpc - no_fix;steamuloabeaujou/api-platform - v2.0.0-rc.1;zfcampus/zf-apigility-documentation-swagger - dev-master;zfcampus/zf-apigility-documentation-swagger - 1.3.0;vsmoraes/swagger-ui-bundle - dev-nelmio_integration;vsmoraes/swagger-ui-bundle - no_fix;fxmonster/l5-swagger - 5.0;kbrabrand/silex-swagger-ui - no_fix;gajendrajain20/laravel-pioneer-cms - no_fix;dandisy/laravel-generator - 1.2.7;dandisy/laravel-generator - dev-dependabot/npm_and_yarn/templates/vuejs/js/eslint-4.19.1;dandisy/laravel-generator - 1.0.0;riverslei/laravel-swagger - no_fix;ServiceStack.Api.Swagger - 4.5.12;ServiceStack.Api.Swagger - 4.0.8;ServiceStack.Api.Swagger - 4.0.35;dandisy/webcore-base - no_fix;dandisy/webcore-base - 1.0.0;damian-nz/l5-swagger - 3.2;damian-nz/l5-swagger - dev-master;davigs/swagger-lume - 2.0;keeko/developer-app - v0.2;jjdoor/swagger-lume - 2.0;iwanli/laravel5-swagger - no_fix;latrell/swagger - 1.0.2;vjeantet/silex-simple-rest-swagger - no_fix;imjarek/laravel-swagger - 5.0;helingfeng/l5-swagger - 5.0;dandisy/adminlte-templates - 1.2.2;OpenRastaSwagger - 1.0.3.21;mahmoodbabaei/etribes-code-challenge - no_fix;open-resource-manager/core - no_fix;pmvc-app/swagger_ui - no_fix;dhawton/l5-swagger-redoc - 3.0.1;dhawton/l5-swagger-redoc - v2.0;dhawton/l5-swagger-redoc - 4.0.1;dolibarr/dolibarr - 9.0.0;mymdz/l5-swagger - 5.0;activelamp/swagger-ui-bundle - dev-nelmio_integration;laminas-api-tools/api-tools-documentation-swagger - 1.3.0;bluzphp/skeleton - 2.0.2;swagger-ui - 2.2.2;pharmit/swaggervel - 1.0.x-dev;jessekoska/swagger-lume - v2.0.24;rich2k/l5-swagger - 5.0;hadeswang/jlapp-swaggervel - 1.0.x-dev;pleio/pleio_rest - no_fix;hos/hos-framework - no_fix;NServiceKit.Api.Swagger - no_fix;luoxiaojun1992/sf - v1.0.0;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-swagger-xml:2.17.1;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.1;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.apache.camel:camel-example-servlet-rest-tomcat:2.15.2;org.webjars.npm:swagger-ui:2.2.8;org.webjars.npm:github-com-jensoleg-swagger-ui:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.jboss.redhat-fuse.apicurio:fuse-apicurito-generator:no_fix;org.webjars.npm:swagger-tools:0.9.16;org.webjars:swagger-ui:2.2.2;io.fabric8.quickstarts.cxf.jaxrs:spring-boot-cxf-jaxrs-xml:no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


