CVE-2019-17495

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
10/10/2019
Last modified:
07/11/2023

Description

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that @import within the JSON data was a functional attack method.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smartbear:swagger_ui:*:*:*:*:*:*:*:* 3.23.11 (excluding)
cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:* 18.1 (including) 18.3 (including)
cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:* 18.1 (including) 18.3 (including)
cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:* 2.4.0 (including) 2.10.0 (including)
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* 16.2.0 (including) 16.2.11 (including)
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* 17.12.0 (including) 17.12.8 (including)
cpe:2.3:a:oracle:utilities_framework:4.3.0.6.0:*:*:*:*:*:*:*