Back

MEDIUM

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks

Published Mar 11, 2022

Description

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 11, 2022
Updated Aug 5, 2024
Reserved Mar 11, 2022
CISA Vulnrichment
Updated Jul 18, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-CR3Q-PQGQ-M8C2