NA

CVE-2023-38337

Published: 14/07/2023 Updated: 27/07/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

rswag prior to 2.10.1 allows remote malicious users to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rswag project rswag