Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

swagger-ui DOM XSS #1076

Closed
blockisec opened this issue Jun 28, 2022 · 4 comments · Fixed by #1604
Closed

swagger-ui DOM XSS #1076

blockisec opened this issue Jun 28, 2022 · 4 comments · Fixed by #1604
Assignees
Labels
dependencies Pull requests that update a dependency file e0-minutes Effort < 60 min e1-hours p1-high

Comments

@blockisec
Copy link

The swagger-ui which is used by docsy is outdated and prune to a DOM XSS vulnerability.

@LisaFC
Copy link
Collaborator

LisaFC commented Jun 30, 2022

@theletterf do you want to take a look at this, I know you added this shortcode?

@theletterf
Copy link
Contributor

Hi there! Sorry, I was on paternity leave.

I guess you'd have to update the swagger-ui dependency, or add it as a dependency even.

@emckean emckean self-assigned this Aug 16, 2022
@chalin chalin mentioned this issue May 4, 2023
14 tasks
@chalin
Copy link
Collaborator

chalin commented May 4, 2023

@theletterf - is this something you are name able to help with? Thanks!

@chalin chalin added dependencies Pull requests that update a dependency file e0-minutes Effort < 60 min e1-hours p1-high labels May 4, 2023
@theletterf
Copy link
Contributor

theletterf commented May 5, 2023

I think so. Let me have a look. Could you assign this one to me?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file e0-minutes Effort < 60 min e1-hours p1-high
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants