SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-25031

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.

MEDIUM 4.3EPSS 42.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 42.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
42.33% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-918, CWE-922
Affected
smartbear/swagger ui
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.