296,746
Total vulnerabilities in the database
Versions of swagger-ui prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to encode output in GET requests. The request is meant to respond with Content-Type application/json which does not trigger the vulnerability but if the web server changes the header to text/html it may allow attackers to execute arbitrary JavaScript.
Upgrade to version 2.2.1 or later.
| Software | From | Fixed in |
|---|---|---|
swagger-ui
|
- | 2.2.1 |