Description
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
Remediation
References
https://community.rapid7.com/community/infosec/blog/2016/09/02/r7-2016-19-persistent-xss-via-unescaped-parameters-in-swagger-ui
Related Vulnerabilities
CVE-2016-6809 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2020-7690 Vulnerability in maven package org.webjars.bowergithub.mrrio:jspdf
CVE-2019-1003031 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project
CVE-2021-21388 Vulnerability in npm package systeminformation
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-beam