Executive brief
swagger-ui is a widely used library for rendering API documentation in web applications. The vulnerability allows attackers to inject malicious scripts through JSON key names, which are displayed in the UI without proper sanitization. When a user views affected documentation, the injected script executes in their browser, potentially enabling session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a Cross-Site Scripting (CWE-79) flaw in swagger-ui's handling of JSON key names during web page generation. The library fails to properly neutralize or escape key names from JSON documents before rendering them in the HTML response. An attacker can craft a malicious JSON file with script tags embedded in object keys; when this file is loaded (either directly or via URL query-string parameter), the unescaped keys are rendered as HTML, causing the scripts to execute. The attack requires user interaction (visiting a link to the malicious documentation) but no authentication. Affected versions are all releases prior to 2.2.1.
Affected products
- Swagger swagger-ui prior to 2.2.1
Timeline
- 2019-12-20: disclosed
- 2022-05-24: patched: advisory published; fix available in version 2.2.1
- 2022-05-24: advisory