Lucene search

K
redhatcveRedhat.comRH:CVE-2016-1000229
HistorySep 20, 2016 - 7:48 a.m.

CVE-2016-1000229

2016-09-2007:48:51
redhat.com
access.redhat.com
8

0.002 Low

EPSS

Percentile

64.7%

It was found that swagger-ui contains a cross site scripting (XSS) vulnerability in the key names in the JSON document. An attacker could use this flaw to supply a key name with script tags which could cause arbitrary code execution. Additionally it is possible to load the arbitrary JSON files remotely via the URL query-string parameter.

0.002 Low

EPSS

Percentile

64.7%

Related for RH:CVE-2016-1000229