vendor:
Swagger UI
by:
Rafael Cintra Lopes
4.3
CVSS
MEDIUM
Misrepresentation of Critical Information
20
CWE
Product Name: Swagger UI
Affected Version From: < 4.1.3
Affected Version To: 4.1.2003
Patch Exists: YES
Related CWE: CVE-2018-25031
CPE: a:swagger:swagger_ui
Platforms Tested:
2023
Swagger UI 4.1.3 – User Interface (UI) Misrepresentation of Critical Information
A vulnerability in Swagger UI 4.1.3 allows an attacker to misrepresent critical information in the user interface. This vulnerability can be exploited by sending a malicious request to the target server, which will then return a response containing the malicious data. The attacker can then use this data to gain access to sensitive information or to perform other malicious activities.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Swagger UI.