GMS-2019-143: Reverse Tabnapping in swagger-ui
(updated )
Versions of swagger-ui
prior to 3.18.0 are vulnerable to Reverse Tabnapping. The package uses target='_blank'
in anchor tags, allowing attackers to access window.opener
for the original page. This is commonly used for phishing attacks.
Recommendation
Upgrade to version 3.18.0 or later.
References
Detect and mitigate GMS-2019-143 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →