Description

Swagger UI is a tool to visualize and interact with your APIs. Certain versions of Swagger UI (between 3.14.1 and 3.38.0) are vulnerable to a DOM-based XSS vulnerability because they are using an outdated version of the library DOMPurify.

Remediation

Upgrade to the latest version of Swagger UI.

References

Related Vulnerabilities