Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22207


fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option can also work around this vulnerability.


Published

2024-01-15T16:15:13.437

Last Modified

2024-11-21T08:55:48.000

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1188

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application smartbear swagger_ui < 2.1.0 Yes

References