First published: Mon Jan 15 2024(Updated: )
### Impact The default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. ### Patches Update to v2.1.0 ### Workarounds Use the `baseDir` option ### References [HackerOne report ](https://hackerone.com/reports/2312369).
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smartbear Swagger Ui | >=2.0.0<2.1.0 | |
npm/@fastify/swagger-ui | >=2.0.0<2.1.0 | 2.1.0 |
>=2.0.0<2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.