Description
Swagger UI is a tool to visualize and interact with your APIs. Certain versions of Swagger UI (between 3.14.1 and 3.38.0) are vulnerable to a DOM-based XSS vulnerability because they are using an outdated version of the library DOMPurify.
Remediation
Upgrade to the latest version of Swagger UI.
References
Related Vulnerabilities
WordPress Plugin Contact Form Clean and Simple Cross-Site Scripting (4.7.0)
WordPress Plugin YOP Poll Multiple Cross-Site Scripting Vulnerabilities (4.9.1)
WordPress Plugin WP eCommerce Multiple Vulnerabilities (3.8.9.5)
Oracle Database Server CVE-2014-2408 Vulnerability (CVE-2014-2408)
WordPress Plugin World Travel Information Cross-Site Scripting (1.0.0)