{"id":"GHSA-p239-93f7-h6xf","summary":"Cross-Site Scripting in swagger-ui","details":"Affected versions of `swagger-ui` contain a cross-site scripting vulnerability in the key names of a specific nested object in the JSON document.\n\n\n## Proof of Concept\nThe vulnerable object structure is:\n```\n{\n    \"definitions\": {\n        \"arbitraryVal\": {\n            \"properties\": {\n                \"\u003cINJECTABLE_KEY_NAME\u003e\": \"LoremIpsum\"\n                }\n            }\n        }\n}\n```\nMalicious JSON documents can be loaded in by providing a URL to them in the `url` query string parameter.\n\n\n\n## Recommendation\n\nUpdate to version 2.2.1 or later.","aliases":["CVE-2016-5682"],"modified":"2023-11-08T03:58:31.570959Z","published":"2020-09-01T15:30:58Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:11:42Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-5682"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/issues/1865"},{"type":"WEB","url":"https://community.rapid7.com/community/infosec/blog/2016/09/02/r7-2016-19-persistent-xss-via-unescaped-parameters-in-swagger-ui"},{"type":"PACKAGE","url":"https://github.com/swagger-api/swagger-ui"},{"type":"WEB","url":"https://www.npmjs.com/advisories/126"}],"affected":[{"package":{"name":"swagger-ui","ecosystem":"npm","purl":"pkg:npm/swagger-ui"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.2.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-p239-93f7-h6xf/GHSA-p239-93f7-h6xf.json"}}],"schema_version":"1.9.0"}