CVE-2019-17495
published 2019-10-10CVE-2019-17495: A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.58%
92.0th percentile
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that @import within the JSON data was a functional attack method.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | 18.1 – 18.3 | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | 18.1 – 18.3 | — |
| oracle | banking_platform | 2.4.0 – 2.10.0 | — |
| oracle | primavera_gateway | 16.2.0 – 16.2.11 | — |
| oracle | primavera_gateway | 17.12.0 – 17.12.8 | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| smartbear | swagger_ui | < 3.23.11 | 3.23.11 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site scripting in Swagger-UI
osv·2019-10-15
CVE-2019-17495 [CRITICAL] Cross-site scripting in Swagger-UI
Cross-site scripting in Swagger-UI
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that @import within the JSON data was a functional attack method.
GHSA
Cross-site scripting in Swagger-UI
ghsa·2019-10-15
CVE-2019-17495 [CRITICAL] CWE-352 Cross-site scripting in Swagger-UI
Cross-site scripting in Swagger-UI
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that @import within the JSON data was a functional attack method.
Oracle
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (Swagger UI) — CVE-2019-17495
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2019-17495 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (Swagger UI) — CVE-2019-17495
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (Swagger UI) vulnerability
CVE: CVE-2019-17495
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Framework (Swagger UI) — CVE-2019-17495
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2019-17495 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Framework (Swagger UI) — CVE-2019-17495
Oracle Oracle Financial Services Applications Risk Matrix: Framework (Swagger UI) vulnerability
CVE: CVE-2019-17495
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (Swagger UI) — CVE-2019-17495
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2019-17495 [CRITICAL] Oracle Oracle Utilities Applications Risk Matrix: General (Swagger UI) — CVE-2019-17495
Oracle Oracle Utilities Applications Risk Matrix: General (Swagger UI) vulnerability
CVE: CVE-2019-17495
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Swagger UI) — CVE-2019-17495
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2019-17495 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Admin (Swagger UI) — CVE-2019-17495
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Swagger UI) vulnerability
CVE: CVE-2019-17495
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
No detection rules found.
No public exploits indexed.
https://github.com/swagger-api/swagger-ui/releases/tag/v3.23.11https://github.com/tarantula-team/CSS-injection-in-Swagger-UIhttps://lists.apache.org/thread.html/r103579b01da2d0aa0f672b88f811224bbf8ef493aaad845895955e91%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r3acb7e494cf1aab99b6784b7c5bbddfd0d4f8a484ab534c3a61ef9cf%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r84b327f7a8b6b28857b906c07a66dd98e1d341191fa8d7816514ef96%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r853ffeb915a400f899de78124d4e0d77a19379d2e11bf8f4e98c624f%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/ref70b940c4f69560d29d6ba792d6c82865e74de3dcad4c92d99b1f8f%40%3Ccommits.airflow.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://github.com/swagger-api/swagger-ui/releases/tag/v3.23.11https://github.com/tarantula-team/CSS-injection-in-Swagger-UIhttps://lists.apache.org/thread.html/r103579b01da2d0aa0f672b88f811224bbf8ef493aaad845895955e91%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r3acb7e494cf1aab99b6784b7c5bbddfd0d4f8a484ab534c3a61ef9cf%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r84b327f7a8b6b28857b906c07a66dd98e1d341191fa8d7816514ef96%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r853ffeb915a400f899de78124d4e0d77a19379d2e11bf8f4e98c624f%40%3Ccommits.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/ref70b940c4f69560d29d6ba792d6c82865e74de3dcad4c92d99b1f8f%40%3Ccommits.airflow.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2019-10-10
Published