-
Notifications
You must be signed in to change notification settings - Fork 6k
Closed
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
WS-2018-0593 - Medium Severity Vulnerability
Vulnerable Library - swagger-ui-3.1.5.jar
WebJar for Swagger UI
Library home page: http://webjars.org
Path to vulnerable library: /he/org.webjars/swagger-ui/jars/swagger-ui-3.1.5.jar
Dependency Hierarchy:
- ❌ swagger-ui-3.1.5.jar (Vulnerable Library)
Found in HEAD commit: 4b7a8d7d7384aa6a27d6309c35ade0916edae7ed
Found in base branch: master
Vulnerability Details
swagger-ui before v3.18.0 is vulnerable to Reverse Tabnabbing. Setting target=_blank\ on anchor tags is unsafe unless used in conjunction with the rel=\noopener\ attribute. A link opened via target blank attribute can make changes to the original page
Publish Date: 2018-08-02
URL: WS-2018-0593
CVSS 3 Score Details (5.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: swagger-api/swagger-ui#4789
Release Date: 2018-08-02
Fix Resolution: v3.18.0
- Check this box to open an automated fix PR
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource