Total vulnerabilities in the database
Versions of swagger-ui
prior to 3.18.0 are vulnerable to Reverse Tabnapping. The package uses target='_blank'
in anchor tags, allowing attackers to access window.opener
for the original page. This is commonly used for phishing attacks.
Upgrade to version 3.18.0 or later.
Software | From | Fixed in |
---|---|---|
![]() |
- | 3.18.0 |