io.springfox:springfox-swagger-ui@2.8.0

  • latest version

    3.0.0

  • first published

    10 years ago

  • latest version published

    5 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the io.springfox:springfox-swagger-ui package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    io.springfox:springfox-swagger-ui is an Automated JSON API documentation for API's built with Spring

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS). This is due to a bypass of a previous XSS vulnerability.

    How to fix Cross-site Scripting (XSS)?

    There is no fixed version for io.springfox:springfox-swagger-ui.

    [0,)
    • M
    Relative Path Overwrite (RPO)

    io.springfox:springfox-swagger-ui is an Automated JSON API documentation for API's built with Spring

    Affected versions of this package are vulnerable to Relative Path Overwrite (RPO). Attackers are able to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value i.e. allows the embedding of untrusted JSON data from remote servers, using <style>@import within the JSON data.

    How to fix Relative Path Overwrite (RPO)?

    Upgrade io.springfox:springfox-swagger-ui to version 2.10.0 or higher.

    [,2.10.0)