Reverse Tabnapping in swagger-ui
Moderate severity
GitHub Reviewed
Published
Jun 20, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 20, 2019
Published to the GitHub Advisory Database
Jun 20, 2019
Last updated
Jan 9, 2023
Versions of
swagger-ui
prior to 3.18.0 are vulnerable to Reverse Tabnapping. The package usestarget='_blank'
in anchor tags, allowing attackers to accesswindow.opener
for the original page. This is commonly used for phishing attacks.Recommendation
Upgrade to version 3.18.0 or later.
References