Bug 1443546 (CVE-2016-5682) - CVE-2016-5682 hawtio-swagger-ui: XSS vulnerability in Definitions section
Summary: CVE-2016-5682 hawtio-swagger-ui: XSS vulnerability in Definitions section
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-5682
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1443549
TreeView+ depends on / blocked
 
Reported: 2017-04-19 12:52 UTC by Adam Mariš
Modified: 2022-01-05 22:25 UTC (History)
9 users (show)

Fixed In Version: hawtio-swagger-ui 2.2.1
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-21 11:52:59 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2017-04-19 12:52:18 UTC
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.

External Reference:

https://community.rapid7.com/community/infosec/blog/2016/09/02/r7-2016-19-persistent-xss-via-unescaped-parameters-in-swagger-ui

Comment 1 Hooman Broujerdi 2017-04-19 23:58:13 UTC
This issue was fixed internally within Red Hat as a part of CVE-2016-1000229 and the fix was released with fuse 6.3 r2. 
https://bugzilla.redhat.com/show_bug.cgi?id=1360275

Comment 2 Joshua Padman 2019-08-12 02:16:05 UTC
This vulnerability is out of security support scope for the following products:
 * Red Hat JBoss A-MQ 6
 * Red Hat JBoss Fuse 6

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.


Note You need to log in before you can comment on or make changes to this bug.