CVE-2024-22207

MEDIUM5.3EPSS 14.4%

Default swagger-ui configuration exposes all files in the module

Published: 1/16/2024Modified: 2/16/2024
Also known as:GHSA-62jr-84gf-wmg4

Description

### Impact The default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. ### Patches Update to v2.1.0 ### Workarounds Use the `baseDir` option ### References [HackerOne report ](https://hackerone.com/reports/2312369).

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (5)