swagger-ui-express-4.1.4.tgz: 2 vulnerabilities (highest severity is: 6.1) #1899
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
wontfix
This will not be worked on
Vulnerable Library - swagger-ui-express-4.1.4.tgz
Path to dependency file: /components/discovery/yarn.lock
Path to vulnerable library: /components/discovery/yarn.lock
Vulnerabilities
Details
CVE-2021-46708
Vulnerable Library - swagger-ui-dist-3.35.1.tgz
[![NPM version](https://badge.fury.io/js/swagger-ui-dist.svg)](http://badge.fury.io/js/swagger-ui-dist)
Library home page: https://registry.npmjs.org/swagger-ui-dist/-/swagger-ui-dist-3.35.1.tgz
Path to dependency file: /components/discovery/yarn.lock
Path to vulnerable library: /components/discovery/yarn.lock
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Publish Date: 2022-03-11
URL: CVE-2021-46708
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-6c9x-mj3g-h47x
Release Date: 2022-03-11
Fix Resolution (swagger-ui-dist): 4.1.3
Direct dependency fix Resolution (swagger-ui-express): 4.2.0
Step up your Open Source Security Game with Mend here
CVE-2018-25031
Vulnerable Library - swagger-ui-dist-3.35.1.tgz
[![NPM version](https://badge.fury.io/js/swagger-ui-dist.svg)](http://badge.fury.io/js/swagger-ui-dist)
Library home page: https://registry.npmjs.org/swagger-ui-dist/-/swagger-ui-dist-3.35.1.tgz
Path to dependency file: /components/discovery/yarn.lock
Path to vulnerable library: /components/discovery/yarn.lock
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
Swagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions.
Publish Date: 2022-03-11
URL: CVE-2018-25031
CVSS 3 Score Details (4.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-qrmm-w75w-3wpx
Release Date: 2022-03-11
Fix Resolution (swagger-ui-dist): 4.1.3
Direct dependency fix Resolution (swagger-ui-express): 4.2.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: