{"id":"GHSA-vgvf-9jh3-fg75","summary":"Deserialization of Untrusted Data in swagger-codegen","details":"A vulnerability in Swagger-Parser's version \u003c= 1.0.30 and Swagger codegen version \u003c= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (\u003c= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.","aliases":["CVE-2017-1000207"],"modified":"2023-11-08T03:58:44.046299Z","published":"2018-10-19T16:46:30Z","database_specific":{"github_reviewed_at":"2020-06-16T21:57:48Z","nvd_published_at":null,"cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000207"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-parser/pull/481"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vgvf-9jh3-fg75"},{"type":"PACKAGE","url":"https://github.com/swagger-api/swagger-parser"},{"type":"WEB","url":"https://lgtm.com/blog/swagger_snakeyaml_CVE-2017-1000207_CVE-2017-1000208"}],"affected":[{"package":{"name":"io.swagger:swagger-parser","ecosystem":"Maven","purl":"pkg:maven/io.swagger/swagger-parser"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.31"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.2","1.0.20","1.0.21","1.0.22","1.0.23","1.0.24","1.0.25","1.0.26","1.0.27","1.0.28","1.0.29","1.0.3","1.0.30","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-vgvf-9jh3-fg75/GHSA-vgvf-9jh3-fg75.json"}},{"package":{"name":"io.swagger:swagger-codegen","ecosystem":"Maven","purl":"pkg:maven/io.swagger/swagger-codegen"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.2"}]}],"versions":["2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.2.0","2.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-vgvf-9jh3-fg75/GHSA-vgvf-9jh3-fg75.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}