CVE-2018-25031: Spoofing attack in swagger-ui
(updated )
Swagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions.
References
- github.com/advisories/GHSA-cr3q-pqgq-m8c2
- github.com/swagger-api/swagger-ui
- github.com/swagger-api/swagger-ui/issues/4872
- github.com/swagger-api/swagger-ui/pull/7697
- github.com/swagger-api/swagger-ui/releases/tag/v4.1.3
- nvd.nist.gov/vuln/detail/CVE-2018-25031
- security.netapp.com/advisory/ntap-20220407-0004
- security.snyk.io/vuln/SNYK-JS-SWAGGERUI-2314885
Code Behaviors & Features
Detect and mitigate CVE-2018-25031 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →