uriel-naor / ISSUES

0 stars 0 forks source link

Update dependency swagger-ui to v3.23.11 - autoclosed #51

Closed uriel-mend-app[bot] closed 1 year ago

uriel-mend-app[bot] commented 1 year ago

This PR contains the following updates:

Package Type Update Change
swagger-ui dependencies minor 3.2.2 -> 3.23.11

By merging this PR, the issue #45 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 9.8 CVE-2019-17495
Medium Medium 5.5 WS-2018-0593
Medium Medium 5.0 WS-2019-0171
Medium Medium 5.0 WS-2019-0172

Release Notes

swagger-api/swagger-ui ### [`v3.23.11`](https://togithub.com/swagger-api/swagger-ui/releases/tag/v3.23.11) [Compare Source](https://togithub.com/swagger-api/swagger-ui/compare/v3.23.10...v3.23.11) ⚠️ **This release contains a security fix that addresses a CSS-based input field value exfiltration vulnerability.** If you use Swagger UI to display untrusted OpenAPI documents, you should upgrade to this version ASAP. ##### Changelog - fix: mitigate "sequential `@import` chaining" vulnerability (via [#​5616](https://togithub.com/swagger-api/swagger-ui/issues/5616)) ### [`v3.23.10`](https://togithub.com/swagger-api/swagger-ui/releases/tag/v3.23.10) [Compare Source](https://togithub.com/swagger-api/swagger-ui/compare/v3.23.9...v3.23.10) This release fixes two bugs: one visual issue within static documentation, and another within runtime validation for Array-typed parameters. ##### Changelog - fix: `