Reverse Tabnapping in swagger-ui
Moderate severity
GitHub Reviewed
Published
Jun 20, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 20, 2019
Published to the GitHub Advisory Database
Jun 20, 2019
Last updated
Jan 9, 2023
Versions of
swagger-uiprior to 3.18.0 are vulnerable to Reverse Tabnapping. The package usestarget='_blank'in anchor tags, allowing attackers to accesswindow.openerfor the original page. This is commonly used for phishing attacks.Recommendation
Upgrade to version 3.18.0 or later.
References