CVE-2019-17495

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-17495
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17495.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-17495
Aliases
Withdrawn
2024-05-15T05:33:16.615792Z
Published
2019-10-10T22:15:10Z
Modified
2023-11-29T07:19:04.240055Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.

References

Affected packages

Git / github.com/swagger-api/swagger-ui

Affected ranges

Type
GIT
Repo
https://github.com/swagger-api/swagger-ui
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

$GIT_TAG

3.*

3.3.1
3.8.1

v/3.*

v/3.18.0

v1.*

v1.0
v1.0.1
v1.0.12
v1.0.13
v1.1.1
v1.1.15
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7

v2.*

v2.0.0
v2.0.1
v2.0.10
v2.0.11
v2.0.12
v2.0.14
v2.0.15
v2.0.16
v2.0.17
v2.0.18
v2.0.19
v2.0.2
v2.0.20
v2.0.21
v2.0.22
v2.0.24
v2.0.3
v2.0.4
v2.0.7
v2.0.8
v2.0.9
v2.1.0
v2.1.0-M1
v2.1.0-M2
v2.1.0-alpha.1
v2.1.0-alpha.4
v2.1.0-alpha.5
v2.1.0-alpha.6
v2.1.1
v2.1.1-M1
v2.1.1-M2
v2.1.2
v2.1.2-M1
v2.1.2-M2
v2.1.3
v2.1.3-M1
v2.1.3-M2
v2.1.4
v2.1.4-M1
v2.1.4-M2
v2.1.5
v2.1.5-M1
v2.1.5-M2
v2.1.6-M1
v2.1.7-M1
v2.1.8-M1
v2.2.0
v2.2.1
v2.2.10
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9

v3.*

v3.0.0
v3.0.1
v3.0.10
v3.0.11
v3.0.12
v3.0.13
v3.0.14
v3.0.15
v3.0.16
v3.0.17
v3.0.18
v3.0.19
v3.0.2
v3.0.20
v3.0.21
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.10.0
v3.11.0
v3.12.0
v3.12.1
v3.12.9
v3.13.0
v3.13.2
v3.13.3
v3.13.4
v3.13.5
v3.13.6
v3.14.0
v3.14.1
v3.14.2
v3.15.0
v3.16.0
v3.17.0
v3.17.1
v3.17.2
v3.17.3
v3.17.4
v3.17.5
v3.17.6
v3.18.0
v3.18.1
v3.18.2
v3.18.3
v3.19.0
v3.19.1
v3.19.2
v3.19.3
v3.19.4
v3.19.5
v3.2.0
v3.2.1
v3.2.2
v3.20.0
v3.20.1
v3.20.2
v3.20.3
v3.20.4
v3.20.5
v3.20.6
v3.20.7
v3.20.8
v3.20.9
v3.21.0
v3.22.0
v3.22.1
v3.22.2
v3.22.3
v3.23.0
v3.23.1
v3.23.10
v3.23.2
v3.23.3
v3.23.4
v3.23.5
v3.23.6
v3.23.7
v3.23.8
v3.23.9
v3.3.0
v3.3.1
v3.3.2
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v3.4.4
v3.4.5
v3.5.0
v3.6.0
v3.6.1
v3.7.0
v3.8.0
v3.8.1
v3.9.0
v3.9.1
v3.9.2