First published: Fri Mar 11 2022(Updated: )
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Smartbear Swagger Ui | <4.1.3 | |
npm/swagger-ui | <4.1.3 | 4.1.3 |
IBM Concert Software | <=1.0.0, 1.0.1, 1.0.2, 1.0.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-25031 is a vulnerability in swagger-ui that could allow a remote attacker to conduct spoofing attacks.
By persuading a victim to open a specially-crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions.
The severity of CVE-2018-25031 is medium, with a CVSS score of 5.4.
IBM Cloud Pak for Business Automation versions V23.0.1 - V23.0.1-IF002, V21.0.3 - V21.0.3-IF024, V22.0.2 - V22.0.2-IF006 and later fixes, V22.0.1 - V22.0.1-IF006 and later fixes, V21.0.2 - V21.0.2-IF012 and later fixes, V21.0.1 - V21.0.1-IF007 and later fixes, V20.0.1 - V20.0.3 and later fixes, V19.0.1 - V19.0.3 and later fixes, and V18.0.0 - V18.0.2 and later fixes are affected by CVE-2018-25031.
To mitigate CVE-2018-25031, users are advised to apply the necessary fixes provided by IBM.