Vulnerabilities/

Server side request forgery in SwaggerUI

Severity:
Medium

Description

SwaggerUI supports displaying remote OpenAPI definitions through the ?url parameter. This enables robust demonstration capabilities on sites like petstore.swagger.io, editor.swagger.io, and similar sites, where users often want to see what their OpenAPI definitions would look like rendered.

Recommendation

Update the swagger-ui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
swagger-ui
Anything's wrong? Let us know Last updated on June 02, 2023

This issue is available in SmartScanner Professional

See Pricing