Description
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
Remediation
References
https://community.rapid7.com/community/infosec/blog/2016/09/02/r7-2016-19-persistent-xss-via-unescaped-parameters-in-swagger-ui
Related Vulnerabilities
CVE-2020-2253 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2021-21631 Vulnerability in maven package org.jenkins-ci.plugins:cloud-stats
CVE-2016-10531 Vulnerability in maven package org.webjars.bower:marked
CVE-2021-22137 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2017-7669 Vulnerability in maven package org.apache.hadoop:hadoop-common