io.swagger:swagger-parser@1.0.25 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the io.swagger:swagger-parser package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Execution

io.swagger:swagger-parser is a simple yet powerful representation of your RESTful API.

Affected versions of this package are vulnerable to Arbitrary Code Execution via the yaml parsing functionality. When a maliciously crafted yaml Open-API specification is parsed, it is possible to execute arbitrary code on the hosting server.

How to fix Arbitrary Code Execution?

Upgrade io.swagger:swagger-parser to version 1.0.31 or higher.

[,1.0.31)