Total vulnerabilities in the database
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.
Software | From | Fixed in |
---|---|---|
smartbear / swagger_ui | - | 3.23.11 |
oracle / utilities_framework | 4.3.0.6.0 | 4.3.0.6.0.x |
oracle / utilities_framework | 4.4.0.0.0 | 4.4.0.0.0.x |
oracle / banking_digital_experience | 19.1 | 19.1.x |
oracle / utilities_framework | 4.4.0.2.0 | 4.4.0.2.0.x |
oracle / banking_digital_experience | 19.2 | 19.2.x |
oracle / banking_digital_experience | 20.1 | 20.1.x |
oracle / primavera_gateway | 16.2.0 | 16.2.11.x |
oracle / banking_platform | 2.4.0 | 2.10.0.x |
oracle / banking_digital_experience | 21.1 | 21.1.x |
oracle / banking_apis | 18.1 | 18.3.x |
oracle / banking_apis | 19.1 | 19.1.x |
oracle / banking_apis | 19.2 | 19.2.x |
oracle / banking_apis | 20.1 | 20.1.x |
oracle / banking_apis | 21.1 | 21.1.x |
oracle / banking_digital_experience | 18.1 | 18.3.x |
oracle / primavera_gateway | 17.12.0 | 17.12.8.x |
![]() |
- | 3.23.11 |