io.springfox%3Aspringfox-swagger-ui@2.5.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the io.springfox%3Aspringfox-swagger-ui package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

io.springfox:springfox-swagger-ui is an Automated JSON API documentation for API's built with Spring

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). This is due to a bypass of a previous XSS vulnerability.

How to fix Cross-site Scripting (XSS)?

There is no fixed version for io.springfox:springfox-swagger-ui.

[0,)
  • M
Relative Path Overwrite (RPO)

io.springfox:springfox-swagger-ui is an Automated JSON API documentation for API's built with Spring

Affected versions of this package are vulnerable to Relative Path Overwrite (RPO). Attackers are able to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value i.e. allows the embedding of untrusted JSON data from remote servers, using <style>@import within the JSON data.

How to fix Relative Path Overwrite (RPO)?

Upgrade io.springfox:springfox-swagger-ui to version 2.10.0 or higher.

[,2.10.0)