Improper Input Validation Affecting swagger-client package, versions <3.27.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Input Validation vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-SWAGGERCLIENT-6836803
  • published13 May 2024
  • disclosed8 May 2024
  • creditglowcloud

Introduced: 8 May 2024

CVE NOT AVAILABLE CWE-20  (opens in a new tab)

How to fix?

Upgrade swagger-client to version 3.27.5 or higher.

Overview

swagger-client is a SwaggerJS - a collection of interfaces for OAI specs

Affected versions of this package are vulnerable to Improper Input Validation due to improper escape of regex expression in the oas3BaseUrl function on index.js.

CVSS Scores

version 3.1