PT-2020-21547 · Swagger · Swagger-Ui
Published
2020-09-11
·
Updated
2020-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
swagger-ui versions prior to 2.2.1
Description
The issue allows HTML code in the
swagger.apiInfo.description value without proper sanitization, which may allow attackers to execute arbitrary JavaScript. This can lead to Cross-Site Scripting (XSS) attacks.Recommendations
Upgrade to version 2.2.1 or later.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swagger-Ui