PT-2022-28238 · Lithium+1 · Lithium+2

Published

2022-09-30

·

Updated

2022-09-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions lithium with Swagger-UI enabled (affected versions not specified)
Description A XSS vulnerability in the provided Swagger-UI is exploitable in applications, allowing an attacker to gain Remote Code Execution (RCE) and potentially exfiltrate secrets in the context of the Swagger session.
Recommendations For lithium with Swagger-UI enabled, update the used swagger-ui by switching to the latest version of dropwizard-swagger. As a temporary workaround, consider setting up a Content-Security-Policy to reduce the risk of injected external content.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-F36P-42JV-8RH2

Affected Products

Swagger-Ui
Dropwizard-Swagger
Lithium