QID 980819
QID 980819: Nodejs (npm) Security Update for swagger-ui (GHSA-c427-hjc3-wrfw)
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c427-hjc3-wrfw for updates pertaining to this vulnerability.
Vendor References
- GHSA-c427-hjc3-wrfw -
github.com/advisories/GHSA-c427-hjc3-wrfw
CVEs related to QID 980819
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c427-hjc3-wrfw | swagger-ui |
|