{"id":"GHSA-f36p-42jv-8rh2","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f36p-42jv-8rh2","summary":"Lithium vulnerable to Cross Site Scripting in provided Swagger-UI","details":"### Impact\nA  XSS vulnerability in the provided (outdated) Swagger-UI is exploitable in applications using lithium with Swagger-UI enabled.\nThis allows an attacker gain Remote Code Execution (RCE) and potentially exfiltrate secrets in the context of this swagger session.\n\n\n### Patches\nThe used swagger-ui was updated by switching to the latest version of dropwizard-swagger in 8b9b406d608fe482ec0e7adf8705834bca92d7df\n\n\n### Workarounds\nThe risk of injected external content can be reduced by setting up a [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy).\n\n\n### References\n* https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/\n\n\n### Credits\nWe thank [Mohit Kumar](https://www.linkedin.com/in/mohit-kumar-4ab6b3bb) for reporting this vulnerability!\n","published":"2022-09-30T04:53:37Z","modified":"2024-11-28T05:29:07.315369Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.wire:lithium","fixedVersion":"3.4.2"},{"ecosystem":"Maven","name":"com.wire.bots:lithium","fixedVersion":null}],"fix":{"url":"https://github.com/wireapp/lithium/commit/8b9b406d608fe482ec0e7adf8705834bca92d7df","label":"wireapp/lithium@8b9b406"},"references":[{"type":"WEB","url":"https://github.com/wireapp/lithium/security/advisories/GHSA-f36p-42jv-8rh2"},{"type":"WEB","url":"https://github.com/wireapp/lithium/commit/8b9b406d608fe482ec0e7adf8705834bca92d7df"},{"type":"PACKAGE","url":"https://github.com/wireapp/lithium"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:29:07.315369Z"}}