Improper Input Validation Affecting swagger-client package, versions <3.27.5


Severity

0.0
medium
0
10

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JS-SWAGGERCLIENT-6836803
  • published 13 May 2024
  • disclosed 8 May 2024
  • credit glowcloud

Introduced: 8 May 2024

CVE NOT AVAILABLE CWE-20 Open this link in a new tab

How to fix?

Upgrade swagger-client to version 3.27.5 or higher.

Overview

swagger-client is a SwaggerJS - a collection of interfaces for OAI specs

Affected versions of this package are vulnerable to Improper Input Validation due to improper escape of regex expression in the oas3BaseUrl function on index.js.

CVSS Scores

version 3.1
Expand this section

Snyk

5.3 medium
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    None
  • Integrity (I)
    None
  • Availability (A)
    Low