{"id":"GHSA-q7pf-qr96-2vq5","summary":"Deserialization of Untrusted Data in swagger-parser","details":"A vulnerability in Swagger-Parser's (version \u003c= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (\u003c= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.","aliases":["CVE-2017-1000208"],"modified":"2023-11-08T03:58:44.108818Z","published":"2018-10-19T16:46:41Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:51:22Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000208"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q7pf-qr96-2vq5"},{"type":"PACKAGE","url":"https://github.com/swagger-api/swagger-parser"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-parser/releases/tag/v1.0.31"},{"type":"WEB","url":"https://lgtm.com/blog/swagger_snakeyaml_CVE-2017-1000207_CVE-2017-1000208"}],"affected":[{"package":{"name":"io.swagger:swagger-codegen","ecosystem":"Maven","purl":"pkg:maven/io.swagger/swagger-codegen"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.2"}]}],"versions":["2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.2.0","2.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-q7pf-qr96-2vq5/GHSA-q7pf-qr96-2vq5.json"}},{"package":{"name":"io.swagger:swagger-parser","ecosystem":"Maven","purl":"pkg:maven/io.swagger/swagger-parser"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.31"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.2","1.0.20","1.0.21","1.0.22","1.0.23","1.0.24","1.0.25","1.0.26","1.0.27","1.0.28","1.0.29","1.0.3","1.0.30","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-q7pf-qr96-2vq5/GHSA-q7pf-qr96-2vq5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}