ZeroHour

CVE-2018-25031

CVSS 3.1
4.3 medium
EPSS
42%p99
Published
()
Modified
Description

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

Vendors
smartbear
Products
swagger ui
Weakness
CWE-20, CWE-918, CWE-922
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.