{"id":"GHSA-22q9-hqm5-mhmc","aliases":[],"url":"https://o3.security/vulnerability/GHSA-22q9-hqm5-mhmc","summary":"Cross-Site Scripting in swagger-ui","details":"Versions of `swagger-ui` prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to encode output in GET requests. The request is meant to respond with Content-Type `application/json` which does not trigger the vulnerability but if the web server changes the header to `text/html` it may allow attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nUpgrade to version 2.2.1 or later.","published":"2020-09-11T21:22:24Z","modified":"2021-09-28T17:01:08Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"swagger-ui","fixedVersion":"2.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/issues/1154"},{"type":"PACKAGE","url":"https://github.com/swagger-api/swagger-ui"},{"type":"WEB","url":"https://www.npmjs.com/advisories/987"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-28T17:01:08Z"}}