{"id":"CVE-2016-1000233","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-1000233","summary":"Cross-Site Scripting in swagger-ui","details":"Affected versions of `swagger-ui` are vulnerable to cross-site scripting. This vulnerability exists because `swagger-ui` automatically executes external Javascript that is loaded in via the `url` query string parameter when a `Content-Type: application/javascript` header is included.\n\nAn attacker can create a server that replies with a malicious script and the proper content-type, and then craft a `swagger-ui` URL that includes the location to their server/script in the `url` query string parameter. When viewed, such a link would execute the attacker's malicious script.\n\n\n## Recommendation\n\nUpdate to 2.2.1 or later.","published":"2020-09-01T15:36:27Z","modified":"2023-11-08T03:58:07.968864Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"swagger-ui","fixedVersion":"2.2.1"}],"fix":{"url":"https://github.com/swagger-api/swagger-ui/commit/331d2be070d89162aa3174a8773ae4a0093f78bc","label":"swagger-api/swagger-ui@331d2be"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000233"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/issues/1863"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/commit/331d2be070d89162aa3174a8773ae4a0093f78bc"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui"},{"type":"WEB","url":"https://www.npmjs.com/advisories/131"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:58:07.968864Z"}}