First published: Tue Jul 26 2016(Updated: )
swagger-ui has XSS in key names
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmartBear Swagger UI | ||
Red Hat JBoss Fuse | =6.3 | |
Red Hat OpenShift | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1000229 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2016-1000229, update to the latest version of the swagger-ui library where the vulnerability is addressed.
CVE-2016-1000229 affects the swagger-ui library, along with specific versions of Red Hat JBoss Fuse and Red Hat OpenShift.
CVE-2016-1000229 is a cross-site scripting (XSS) vulnerability that can be exploited through malformed JSON documents.
Yes, CVE-2016-1000229 can be exploited remotely if an attacker can manipulate the JSON response delivered by the affected applications.