GHSA-f36p-42jv-8rh2
Dashboard / Vulnerabilities / GHSA-f36p-42jv-8rh2
GHSA-f36p-42jv-8rh2
Summary: Lithium vulnerable to Cross Site Scripting in provided Swagger-UI
Details: ### Impact A XSS vulnerability in the provided (outdated) Swagger-UI is exploitable in applications using lithium with Swagger-UI enabled. This allows an attacker gain Remote Code Execution (RCE) and potentially exfiltrate secrets in the context of this swagger session. ### Patches The used swagger-ui was updated by switching to the latest version of dropwizard-swagger in 8b9b406d608fe482ec0e7adf8705834bca92d7df ### Workarounds The risk of injected external content can be reduced by setting up a [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy). ### References * https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/ ### Credits We thank [Mohit Kumar](https://www.linkedin.com/in/mohit-kumar-4ab6b3bb) for reporting this vulnerability!
References: https://github.com/wireapp/lithium/security/advisories/GHSA-f36p-42jv-8rh2, https://github.com/wireapp/lithium/commit/8b9b406d608fe482ec0e7adf8705834bca92d7df, https://github.com/wireapp/lithium
Affected packages
Package
Name: com.wire:lithium
Purl: pkg:maven/com.wire/lithium
Affected ranges
Type: ECOSYSTEM
Events:
