Executive brief
Swagger UI is a library for displaying API documentation. The tool supports loading remote API definitions via a URL parameter, which can be abused in phishing attacks. An attacker can trick users into clicking a link to a legitimate organization's Swagger UI instance (e.g., example.com) but with a malicious URL parameter pointing to a fake API, causing users to unknowingly submit credentials or sensitive data to the attacker's server.
Technical details
Swagger UI versions prior to 4.1.3 allow the ?url query parameter to load remote OpenAPI definitions without restriction. The vulnerability is a server-side request forgery (SSRF) and phishing attack vector where an attacker crafts a URL like https://example.com/api-docs?url=https://evildomain/fakeapi.yaml. When a user clicks this link and uses the "Try-it-out" feature to test APIs, requests are sent to the attacker's server. The attack requires user interaction (clicking the malicious link and submitting data) and cannot be exploited non-interactively for code injection or XSS. The fix, released in version 4.1.3, disables the ?url parameter by default; administrators can re-enable it if needed.
Affected products
- Swagger Swagger UI < 4.1.3
- Swagger Swagger UI Dist < 4.1.3
- Swagger Swagger UI React < 4.1.3
- Swashbuckle Swashbuckle.AspNetCore.SwaggerUI versions with vulnerable Swagger UI
Timeline
- 2021-12-09: disclosed: Advisory published
- 2021-12: patched: Version 4.1.3 released with query parameters disabled by default