{"id":"GHSA-c427-hjc3-wrfw","summary":"Cross-site scripting in Swagger-UI","details":"A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that \u003cstyle\u003e@import within the JSON data was a functional attack method.","aliases":["CVE-2019-17495"],"modified":"2024-08-26T16:01:07.108462Z","published":"2019-10-15T19:27:05Z","database_specific":{"cwe_ids":["CWE-352","CWE-79"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-10-14T20:13:46Z","nvd_published_at":"2019-10-10T22:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-17495"},{"type":"WEB","url":"https://github.com/springfox/springfox/commit/26f72f0d16b166e12c20255a4ee907dc10685cf8"},{"type":"PACKAGE","url":"https://github.com/swagger-api/swagger-ui"},{"type":"WEB","url":"https://github.com/swagger-api/swagger-ui/releases/tag/v3.23.11"},{"type":"WEB","url":"https://github.com/tarantula-team/CSS-injection-in-Swagger-UI"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r103579b01da2d0aa0f672b88f811224bbf8ef493aaad845895955e91@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r3acb7e494cf1aab99b6784b7c5bbddfd0d4f8a484ab534c3a61ef9cf@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r84b327f7a8b6b28857b906c07a66dd98e1d341191fa8d7816514ef96@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r853ffeb915a400f899de78124d4e0d77a19379d2e11bf8f4e98c624f@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ref70b940c4f69560d29d6ba792d6c82865e74de3dcad4c92d99b1f8f@%3Ccommits.airflow.apache.org%3E"},{"type":"WEB","url":"https://security.snyk.io/vuln/maven?search=CVE-2019-17495"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"}],"affected":[{"package":{"name":"swagger-ui","ecosystem":"npm","purl":"pkg:npm/swagger-ui"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.23.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-c427-hjc3-wrfw/GHSA-c427-hjc3-wrfw.json"}},{"package":{"name":"org.webjars:swagger-ui","ecosystem":"Maven","purl":"pkg:maven/org.webjars/swagger-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.23.11"}]}],"versions":["2.0.12","2.0.14","2.0.14-1","2.0.17","2.0.18","2.0.21","2.0.22","2.0.24","2.1.0","2.1.0-M1","2.1.0-alpha.6","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.8-M1","2.2.0","2.2.10","2.2.10-1","2.2.2","2.2.5","2.2.6","2.2.8","3.0.10","3.0.14","3.0.17","3.0.18","3.0.19","3.0.2","3.0.20","3.0.21","3.0.3","3.0.4","3.0.5","3.0.7","3.0.8","3.1.2","3.1.4","3.1.5","3.1.6","3.1.7","3.10.0","3.11.0","3.12.0","3.12.1","3.13.0","3.13.1","3.13.2","3.13.3","3.13.4","3.13.6","3.14.0","3.14.2","3.17.0","3.17.1","3.17.2","3.17.3","3.17.4","3.17.6","3.18.1","3.18.2","3.19.0","3.19.4","3.19.5","3.2.0","3.2.2","3.20.0","3.20.1","3.20.2","3.20.3","3.20.5","3.20.8","3.20.9","3.22.0","3.22.1","3.22.2","3.23.0","3.23.2","3.23.4","3.23.5","3.23.8","3.4.4","3.5.0","3.6.1","3.7.0","3.8.0","3.9.0","3.9.1","3.9.2","3.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-c427-hjc3-wrfw/GHSA-c427-hjc3-wrfw.json"}},{"package":{"name":"org.webjars.npm:swagger-ui","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/swagger-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.23.11"}]}],"versions":["2.1.3","2.1.4","2.1.5","2.2.0","2.2.10","2.2.8","3.0.12","3.0.14","3.0.17","3.0.18","3.0.2","3.0.20","3.0.6","3.1.4","3.1.6","3.1.7","3.10.0","3.12.0","3.17.0","3.17.6","3.18.1","3.19.0","3.19.1","3.19.4","3.20.6","3.20.7","3.22.0","3.22.1","3.22.2","3.22.3","3.23.1","3.23.10","3.23.2","3.23.3","3.23.4","3.23.5","3.3.1","3.4.1","3.6.1","3.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-c427-hjc3-wrfw/GHSA-c427-hjc3-wrfw.json"}},{"package":{"name":"io.springfox:springfox-swagger-ui","ecosystem":"Maven","purl":"pkg:maven/io.springfox/springfox-swagger-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.0"}]}],"versions":["2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.2.2","2.3.0","2.3.1","2.4.0","2.5.0","2.6.0","2.6.1","2.7.0","2.8.0","2.9.1","2.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-c427-hjc3-wrfw/GHSA-c427-hjc3-wrfw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}