5.28.0
9 years ago
15 days ago
Known vulnerabilities in the org.webjars.npm:swagger-ui package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.webjars.npm:swagger-ui is a WebJar npm bundle for swagger-ui. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the NOTE: This vulnerability has also been identified as: CVE-2018-25031 How to fix Server-side Request Forgery (SSRF)? Upgrade | [0,4.1.3) |
org.webjars.npm:swagger-ui is a WebJar npm bundle for swagger-ui. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the NOTE: This vulnerability has also been identified as: CVE-2021-46708 How to fix Server-side Request Forgery (SSRF)? Upgrade | [0,4.1.3) |
org.webjars.npm:swagger-ui is a WebJar npm bundle for swagger-ui. Affected versions of this package are vulnerable to Insecure Defaults. Markdown rendering allows How to fix Insecure Defaults? Upgrade | [,3.26.1) |
org.webjars.npm:swagger-ui is a WebJar npm bundle for swagger-ui. Affected versions of this package are vulnerable to Relative Path Overwrite (RPO). Attackers are able to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value i.e. allows the embedding of untrusted JSON data from remote servers, using How to fix Relative Path Overwrite (RPO)? Upgrade | [,3.23.11) |
org.webjars.npm:swagger-ui is a WebJar npm bundle for swagger-ui. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to a lack of sanitization of URLs used for OAuth auth flow. How to fix Cross-site Scripting (XSS)? Upgrade | [,3.22.0) |
org.webjars.npm:swagger-ui is a WebJar npm bundle for swagger-ui. Affected versions of this package are vulnerable to Reverse Tabnabbing. Setting How to fix Reverse Tabnabbing? Upgrade | [,3.18.1) |
org.webjars.npm:swagger-ui is a WebJar npm bundle for swagger-ui. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to insertion of How to fix Cross-site Scripting (XSS)? Upgrade | [,3.6.1) |