QID 980696
QID 980696: Nodejs (npm) Security Update for swagger-ui (GHSA-mrx7-8hxf-f853)
Affected versions of `swagger-ui` are vulnerable to cross-site scripting. This vulnerability exists because `swagger-ui` automatically executes external Javascript that is loaded in via the `url` query string parameter when a `Content-Type: application/javascript` header is included.
An attacker can create a server that replies with a malicious script and the proper content-type, and then craft a `swagger-ui` URL that includes the location to their server/script in the `url` query string parameter. When viewed, such a link would execute the attacker's malicious script.
## Recommendation
Update to 2.2.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mrx7-8hxf-f853 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mrx7-8hxf-f853 -
github.com/advisories/GHSA-mrx7-8hxf-f853
CVEs related to QID 980696
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mrx7-8hxf-f853 | swagger-ui |
|