GHSA-62jr-84gf-wmg4
Dashboard / Vulnerabilities / GHSA-62jr-84gf-wmg4
Summary: Default swagger-ui configuration exposes all files in the module
Details: ### Impact The default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. ### Patches Update to v2.1.0 ### Workarounds Use the `baseDir` option ### References [HackerOne report ](https://hackerone.com/reports/2312369).
References: https://github.com/fastify/fastify-swagger-ui/security/advisories/GHSA-62jr-84gf-wmg4, https://nvd.nist.gov/vuln/detail/CVE-2024-22207, https://github.com/fastify/fastify-swagger-ui/commit/13d799a2c5f14d3dd5b15892e03bbcbae63ee6f7, https://github.com/fastify/fastify-swagger-ui, https://security.netapp.com/advisory/ntap-20240216-0002
Affected packages
Package
Name: @fastify/swagger-ui
Purl: pkg:npm/%40fastify/swagger-ui
Affected ranges
Type: SEMVER
Events:
