Description
Swagger UI is a tool to visualize and interact with your APIs. Certain versions of Swagger UI (between 3.14.1 and 3.38.0) are vulnerable to a DOM-based XSS vulnerability because they are using an outdated version of the library DOMPurify.
Remediation
Upgrade to the latest version of Swagger UI.
References
Related Vulnerabilities
Oracle Database Server CVE-2006-0263 Vulnerability (CVE-2006-0263)
WordPress Plugin Google Analytics Dashboard Cross-Site Scripting (2.1.1)
MySQL CVE-2020-14614 Vulnerability (CVE-2020-14614)
MediaWiki Incorrect Authorization Vulnerability (CVE-2022-29906)
WordPress Plugin 3DPrint Cross-Site Request Forgery (3.5.4.7)