{"id":"GHSA-x9p2-fxq6-2m5f","aliases":[],"url":"https://o3.security/vulnerability/GHSA-x9p2-fxq6-2m5f","summary":"Reverse Tabnapping in swagger-ui","details":"Versions of `swagger-ui` prior to 3.18.0 are vulnerable to [Reverse Tabnapping](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page. This is commonly used for phishing attacks.\n\n\n## Recommendation\n\nUpgrade to version 3.18.0 or later.","published":"2019-06-20T14:33:07Z","modified":"2021-08-16T23:44:47Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"swagger-ui","fixedVersion":"3.18.0"}],"fix":{"url":"https://github.com/swagger-api/swagger-ui/pull/4789","label":"swagger-api/swagger-ui#4789"},"references":[{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/pull/4789"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/commit/3f4cae3334fdd492a373f4453bd03a9ebd87becf"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/releases/tag/v3.18.0"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-SWAGGERUI-449808"},{"type":"WEB","url":"https://www.npmjs.com/advisories/975"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-08-16T23:44:47Z"}}