You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
swagger-ui is a library that allows interaction and visualisation of APIs.
Affected versions of this package are vulnerable to User Interface (UI) Misrepresentation of Critical Information via the ?url parameter, which was intended to allow displaying remote OpenAPI definitions. This functionality may pose a risk for users who host their own SwaggerUI instances. In particular, including remote OpenAPI definitions opens a vector for phishing attacks by abusing the trusted names/domains of self-hosted instances.
Overview
swagger-ui is a library that allows interaction and visualisation of APIs.
Affected versions of this package are vulnerable to User Interface (UI) Misrepresentation of Critical Information via the
?url
parameter, which was intended to allow displaying remote OpenAPI definitions. This functionality may pose a risk for users who host their own SwaggerUI instances. In particular, including remote OpenAPI definitions opens a vector for phishing attacks by abusing the trusted names/domains of self-hosted instances.Remediation
Upgrade
swagger-ui
to version 4.1.3 or higher.References
The text was updated successfully, but these errors were encountered: