Vulnerabilities/

Spoofing attack in swagger-ui-dist

Severity:
Medium

Description

The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim’s click actions and possibly launch further attacks against the victim.

Recommendation

Update the swagger-ui-dist package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
swagger-ui-dist
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing