Rswag · Rswag · CVE-2023-38337
**Name of the Vulnerable Software and Affected Versions**
rswag versions prior to 2.10.1
**Description**
The issue allows remote attackers to read arbitrary JSON and YAML files via directory traversal. This occurs because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.
**Recommendations**
For versions prior to 2.10.1, update to version 2.10.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the rswag-api to minimize the risk of exploitation.