Lucene search

K
githubGitHub Advisory DatabaseGHSA-C427-HJC3-WRFW
HistoryOct 15, 2019 - 7:27 p.m.

Cross-site scripting in Swagger-UI

2019-10-1519:27:05
CWE-79
CWE-352
GitHub Advisory Database
github.com
34

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.017

Percentile

88.0%

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.

Affected configurations

Vulners
Node
io.springfoxspringfox-swagger-uiRange<2.10.0
OR
org.webjars.npmswagger-uiRange<3.23.11
OR
org.webjarsswagger-uiRange<3.23.11
OR
smartbearswagger-uiRange<3.23.11
VendorProductVersionCPE
io.springfoxspringfox-swagger-ui*cpe:2.3:a:io.springfox:springfox-swagger-ui:*:*:*:*:*:*:*:*
org.webjars.npmswagger-ui*cpe:2.3:a:org.webjars.npm:swagger-ui:*:*:*:*:*:*:*:*
org.webjarsswagger-ui*cpe:2.3:a:org.webjars:swagger-ui:*:*:*:*:*:*:*:*
smartbearswagger-ui*cpe:2.3:a:smartbear:swagger-ui:*:*:*:*:*:*:*:*

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.017

Percentile

88.0%