See how http-swagger project compares to other vendors in security performance
Impact Allows an attacker to perform a DOS attack consisting of memory exhaustion on the host system.
Patches Yes. Please upgrade to v1.2.6.
Workarounds A workaround is to restrict the path prefix to the "GET" method. As shown below func main() { r := mux.NewRouter()
r.PathPrefix("/swagger/").Handler(httpSwagger.Handler( httpSwagger.URL("http://localhost:1323/swagger/doc.json"), //The url pointing to API definition httpSwagger.DeepLinking(true), httpSwagger.DocExpansion("none"), httpSwagger.DomID("#swagger-ui"), )).Methods(http.MethodGet)
References Reporter dongguangli from https://www.huoxian.cn/ company
For more information If you have any questions or comments about this advisory: Open an issue in http-swagger
http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and webdav.memFile) can subsequently be accessed via a GET request. NOTE: this is independently fixable with respect to CVE-2022-24863, because (if a solution continued to allow PUT requests) large files could have been blocked without blocking JavaScript, or JavaScript could have been blocked without blocking large files.