quanted / hms_kube

HMS kubernetes stack
0 stars 0 forks source link

OpenAPI update to patch exploit #15

Open deronsmith opened 2 years ago

deronsmith commented 2 years ago

Update openAPI to the latest version to resolve configUrl overwrite exploit.

https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/

deronsmith commented 2 years ago

Updated swagger UI version, tested exploit and properly prevents behavior.