Junglewise Threat Intelligence

CVE-2016-1000229: swagger-ui cross-site scripting in key names

CVE-2016-1000229 · Severity: low · CVSS 3.1 · Published 2022-05-24

Technologies: swagger-ui (npm). Vendors: npm.

Executive brief

swagger-ui is a widely used library for rendering API documentation in web applications. The vulnerability allows attackers to inject malicious scripts through JSON key names, which are displayed in the UI without proper sanitization. When a user views affected documentation, the injected script executes in their browser, potentially enabling session hijacking, credential theft, or malware distribution.

Technical details

The vulnerability is a Cross-Site Scripting (CWE-79) flaw in swagger-ui's handling of JSON key names during web page generation. The library fails to properly neutralize or escape key names from JSON documents before rendering them in the HTML response. An attacker can craft a malicious JSON file with script tags embedded in object keys; when this file is loaded (either directly or via URL query-string parameter), the unescaped keys are rendered as HTML, causing the scripts to execute. The attack requires user interaction (visiting a link to the malicious documentation) but no authentication. Affected versions are all releases prior to 2.2.1.

Affected products

  • Swagger swagger-ui prior to 2.2.1

Timeline

  • 2019-12-20: disclosed
  • 2022-05-24: patched: advisory published; fix available in version 2.2.1
  • 2022-05-24: advisory

References

Related threats