PT-2020-20945 · Swagger · Swagger-Ui

Published

2020-09-11

·

Updated

2020-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions swagger-ui versions prior to 2.2.1
Description The issue arises from the failure to encode output in GET requests. Normally, the response has a Content-Type of application/json, which does not trigger the issue. However, if the web server alters the header to text/html, it may enable attackers to execute arbitrary JavaScript, leading to Cross-Site Scripting (XSS).
Recommendations Upgrade to version 2.2.1 or later.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-22Q9-HQM5-MHMC

Affected Products

Swagger-Ui