GHSA-f36p-42jv-8rh2

    Dashboard / Vulnerabilities / GHSA-f36p-42jv-8rh2

    GHSA-f36p-42jv-8rh2

    Published: 30 Sept 2022Last Modified: 28 Nov 2024

    Summary: Lithium vulnerable to Cross Site Scripting in provided Swagger-UI

    Details: ### Impact A XSS vulnerability in the provided (outdated) Swagger-UI is exploitable in applications using lithium with Swagger-UI enabled. This allows an attacker gain Remote Code Execution (RCE) and potentially exfiltrate secrets in the context of this swagger session. ### Patches The used swagger-ui was updated by switching to the latest version of dropwizard-swagger in 8b9b406d608fe482ec0e7adf8705834bca92d7df ### Workarounds The risk of injected external content can be reduced by setting up a [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy). ### References * https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/ ### Credits We thank [Mohit Kumar](https://www.linkedin.com/in/mohit-kumar-4ab6b3bb) for reporting this vulnerability!

    Affected packages

    Package

    Name: com.wire:lithium

    Purl: pkg:maven/com.wire/lithium

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.4.2

    Affected versions

    3.3.0
    3.3.1
    3.3.2
    3.3.3
    3.3.4
    3.3.5
    3.3.6
    3.3.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-f36p-42jv-8rh2 | CVE-DB