Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-25031


Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.


Published

2022-03-11T07:15:07.190

Last Modified

2024-11-21T04:03:23.847

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20
  • Type: Secondary
    CWE-20
    CWE-918
    CWE-922

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application smartbear swagger_ui < 4.1.3 Yes

References