Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM0MjctaGpjMy13cmZ3
Cross-site scripting in Swagger-UI
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that @import within the JSON data was a functional attack method.
Permalink: https://github.com/advisories/GHSA-c427-hjc3-wrfwJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM0MjctaGpjMy13cmZ3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 5 years ago
Updated: 3 months ago
CVSS Score: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-c427-hjc3-wrfw, CVE-2019-17495
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-17495
- https://github.com/swagger-api/swagger-ui/releases/tag/v3.23.11
- https://github.com/tarantula-team/CSS-injection-in-Swagger-UI
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://lists.apache.org/thread.html/r103579b01da2d0aa0f672b88f811224bbf8ef493aaad845895955e91@%3Ccommits.airflow.apache.org%3E
- https://lists.apache.org/thread.html/r3acb7e494cf1aab99b6784b7c5bbddfd0d4f8a484ab534c3a61ef9cf@%3Ccommits.airflow.apache.org%3E
- https://lists.apache.org/thread.html/r84b327f7a8b6b28857b906c07a66dd98e1d341191fa8d7816514ef96@%3Ccommits.airflow.apache.org%3E
- https://lists.apache.org/thread.html/r853ffeb915a400f899de78124d4e0d77a19379d2e11bf8f4e98c624f@%3Ccommits.airflow.apache.org%3E
- https://lists.apache.org/thread.html/ref70b940c4f69560d29d6ba792d6c82865e74de3dcad4c92d99b1f8f@%3Ccommits.airflow.apache.org%3E
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://github.com/springfox/springfox/commit/26f72f0d16b166e12c20255a4ee907dc10685cf8
- https://security.snyk.io/vuln/maven?search=CVE-2019-17495
- https://github.com/advisories/GHSA-c427-hjc3-wrfw
Blast Radius: 87.4
Affected Packages
maven:io.springfox:springfox-swagger-ui
Dependent packages: 1,186Dependent repositories: 98,562
Downloads:
Affected Version Ranges: < 2.10.0
Fixed in: 2.10.0
All affected versions: 2.0.1, 2.0.3, 2.1.0, 2.1.1, 2.1.2, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.5.0, 2.6.0, 2.6.1, 2.7.0, 2.8.0, 2.9.1, 2.9.2
All unaffected versions: 2.10.0, 2.10.1, 2.10.2, 2.10.3, 2.10.4, 2.10.5, 3.0.0
maven:org.webjars.npm:swagger-ui
Dependent packages: 1Dependent repositories: 0
Downloads:
Affected Version Ranges: < 3.23.11
Fixed in: 3.23.11
All affected versions: 2.1.3, 2.1.4, 2.1.5, 2.2.0, 2.2.8, 2.2.10, 3.0.2, 3.0.6, 3.0.12, 3.0.14, 3.0.17, 3.0.18, 3.0.20, 3.1.4, 3.1.6, 3.1.7, 3.3.1, 3.4.1, 3.6.1, 3.9.3, 3.10.0, 3.12.0, 3.17.0, 3.17.6, 3.18.1, 3.19.0, 3.19.1, 3.19.4, 3.20.6, 3.20.7, 3.22.0, 3.22.1, 3.22.2, 3.22.3, 3.23.1, 3.23.2, 3.23.3, 3.23.4, 3.23.5, 3.23.10
All unaffected versions: 3.23.11, 3.24.0, 3.24.1, 3.24.2, 3.24.3, 3.25.0, 3.25.3, 3.26.0, 3.26.1, 3.26.2, 3.27.0, 3.29.0, 3.45.0, 3.45.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.52.2, 3.52.3, 3.52.4, 4.1.0, 4.5.1, 4.8.0, 4.8.1, 4.10.0, 4.10.3, 4.11.0, 4.14.2, 4.14.3, 4.15.2, 4.15.5, 4.16.1, 4.18.2, 4.19.0, 5.4.2, 5.5.0, 5.6.2, 5.11.3, 5.17.14
maven:org.webjars:swagger-ui
Dependent packages: 228Dependent repositories: 1,444
Downloads:
Affected Version Ranges: < 3.23.11
Fixed in: 3.23.11
All affected versions: 2.0.12, 2.0.14, 2.0.17, 2.0.18, 2.0.21, 2.0.22, 2.0.24, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.2.0, 2.2.2, 2.2.5, 2.2.6, 2.2.8, 2.2.10, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.7, 3.0.8, 3.0.10, 3.0.14, 3.0.17, 3.0.18, 3.0.19, 3.0.20, 3.0.21, 3.1.2, 3.1.4, 3.1.5, 3.1.6, 3.1.7, 3.2.0, 3.2.2, 3.4.4, 3.5.0, 3.6.1, 3.7.0, 3.8.0, 3.9.0, 3.9.1, 3.9.2, 3.9.3, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.13.1, 3.13.2, 3.13.3, 3.13.4, 3.13.6, 3.14.0, 3.14.2, 3.17.0, 3.17.1, 3.17.2, 3.17.3, 3.17.4, 3.17.6, 3.18.1, 3.18.2, 3.19.0, 3.19.4, 3.19.5, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.20.5, 3.20.8, 3.20.9, 3.22.0, 3.22.1, 3.22.2, 3.23.0, 3.23.2, 3.23.4, 3.23.5, 3.23.8
All unaffected versions: 3.23.11, 3.24.0, 3.24.2, 3.24.3, 3.25.0, 3.25.1, 3.25.2, 3.25.3, 3.25.4, 3.25.5, 3.26.0, 3.26.1, 3.27.0, 3.28.0, 3.30.0, 3.31.1, 3.32.1, 3.32.3, 3.32.5, 3.34.0, 3.35.0, 3.35.1, 3.35.2, 3.36.0, 3.36.1, 3.36.2, 3.37.0, 3.37.2, 3.38.0, 3.40.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.45.0, 3.46.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.51.1, 3.51.2, 3.52.1, 3.52.3, 3.52.5, 4.0.0, 4.0.1, 4.1.0, 4.1.2, 4.1.3, 4.2.0, 4.2.1, 4.4.1, 4.5.0, 4.5.2, 4.6.2, 4.8.0, 4.8.1, 4.9.1, 4.10.3, 4.11.1, 4.13.2, 4.14.0, 4.14.1, 4.14.2, 4.14.3, 4.15.0, 4.15.5, 4.17.0, 4.17.1, 4.18.0, 4.18.1, 4.18.2, 4.19.0, 4.19.1, 5.0.0, 5.1.0, 5.1.2, 5.1.3, 5.2.0, 5.3.1, 5.4.2, 5.5.0, 5.6.1, 5.7.2, 5.9.0, 5.10.3, 5.11.8, 5.11.9, 5.11.10, 5.12.0, 5.12.2, 5.13.0, 5.14.0, 5.15.0, 5.15.1, 5.15.2, 5.17.0, 5.17.1, 5.17.2, 5.17.6, 5.17.7, 5.17.11, 5.17.14, 5.18.0, 5.18.1, 5.18.2
npm:swagger-ui
Dependent packages: 173Dependent repositories: 8,484
Downloads: 861,909 last month
Affected Version Ranges: < 3.23.11
Fixed in: 3.23.11
All affected versions: 0.1.11, 0.1.12, 0.1.13, 0.1.14, 1.1.15, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.8, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16, 2.0.17, 2.0.18, 2.0.19, 2.0.20, 2.0.21, 2.0.22, 2.0.24, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.2.0, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.8, 2.2.9, 2.2.10, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, 3.0.12, 3.0.13, 3.0.14, 3.0.15, 3.0.16, 3.0.17, 3.0.18, 3.0.19, 3.0.20, 3.0.21, 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.1.7, 3.2.0, 3.2.1, 3.2.2, 3.3.0, 3.3.1, 3.3.2, 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.5.0, 3.6.0, 3.6.1, 3.7.0, 3.8.0, 3.8.1, 3.9.0, 3.9.1, 3.9.2, 3.9.3, 3.10.0, 3.11.0, 3.12.0, 3.12.1, 3.13.0, 3.13.1, 3.13.2, 3.13.3, 3.13.4, 3.13.5, 3.13.6, 3.14.0, 3.14.1, 3.14.2, 3.15.0, 3.16.0, 3.17.0, 3.17.1, 3.17.2, 3.17.3, 3.17.5, 3.17.6, 3.18.0, 3.18.1, 3.18.2, 3.18.3, 3.19.0, 3.19.1, 3.19.2, 3.19.3, 3.19.4, 3.19.5, 3.20.0, 3.20.1, 3.20.2, 3.20.3, 3.20.4, 3.20.5, 3.20.6, 3.20.7, 3.20.8, 3.20.9, 3.20.10, 3.21.0, 3.22.0, 3.22.1, 3.22.2, 3.22.3, 3.23.0, 3.23.1, 3.23.2, 3.23.3, 3.23.4, 3.23.5, 3.23.6, 3.23.7, 3.23.8, 3.23.9, 3.23.10
All unaffected versions: 3.23.11, 3.24.0, 3.24.1, 3.24.2, 3.24.3, 3.25.0, 3.25.1, 3.25.2, 3.25.3, 3.25.4, 3.25.5, 3.26.0, 3.26.1, 3.26.2, 3.27.0, 3.28.0, 3.29.0, 3.30.0, 3.30.1, 3.30.2, 3.31.0, 3.31.1, 3.32.0, 3.32.1, 3.32.2, 3.32.3, 3.32.4, 3.32.5, 3.33.0, 3.34.0, 3.35.0, 3.35.1, 3.35.2, 3.36.0, 3.36.1, 3.36.2, 3.37.0, 3.37.1, 3.37.2, 3.38.0, 3.39.0, 3.40.0, 3.41.0, 3.41.1, 3.42.0, 3.43.0, 3.44.0, 3.44.1, 3.45.0, 3.45.1, 3.46.0, 3.47.0, 3.47.1, 3.48.0, 3.49.0, 3.50.0, 3.51.0, 3.51.1, 3.51.2, 3.52.0, 3.52.1, 3.52.2, 3.52.3, 3.52.4, 3.52.5, 4.0.0, 4.0.1, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.2.0, 4.2.1, 4.3.0, 4.4.0, 4.4.1, 4.5.0, 4.5.1, 4.5.2, 4.6.0, 4.6.1, 4.6.2, 4.7.0, 4.8.0, 4.8.1, 4.9.0, 4.9.1, 4.10.0, 4.10.1, 4.10.2, 4.10.3, 4.11.0, 4.11.1, 4.12.0, 4.13.0, 4.13.1, 4.13.2, 4.14.0, 4.14.1, 4.14.2, 4.14.3, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.15.4, 4.15.5, 4.16.0, 4.16.1, 4.17.0, 4.17.1, 4.18.0, 4.18.1, 4.18.2, 4.18.3, 4.19.0, 4.19.1, 5.0.0, 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.2.0, 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1, 5.4.2, 5.5.0, 5.6.0, 5.6.1, 5.6.2, 5.7.0, 5.7.1, 5.7.2, 5.8.0, 5.9.0, 5.9.1, 5.9.2, 5.9.3, 5.9.4, 5.10.0, 5.10.1, 5.10.2, 5.10.3, 5.10.4, 5.10.5, 5.11.0, 5.11.1, 5.11.2, 5.11.3, 5.11.4, 5.11.5, 5.11.6, 5.11.7, 5.11.8, 5.11.9, 5.11.10, 5.12.0, 5.12.1, 5.12.2, 5.12.3, 5.13.0, 5.14.0, 5.15.0, 5.15.1, 5.15.2, 5.16.0, 5.16.1, 5.16.2, 5.17.0, 5.17.1, 5.17.2, 5.17.3, 5.17.4, 5.17.5, 5.17.6, 5.17.7, 5.17.8, 5.17.9, 5.17.10, 5.17.11, 5.17.12, 5.17.13, 5.17.14, 5.18.0, 5.18.1, 5.18.2