Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-25031

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.821
EPSS Ranking 99.1%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.3
Products affected by CVE-2018-25031


Contact Us

Shodan ® - All rights reserved