rswag
Generate beautiful API documentation, including a UI to explore and test operations, directly from your rspec integration tests. OpenAPI 2 and 3 supported. More about the OpenAPI initiative here: http://spec.openapis.org/
Activity
- Latest release
- 10mo ago
- Total releases
- 46
- Cadence
- ~27 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Oct 12, 2016
| Version | Released | |
|---|---|---|
2.17.0
minor
| ||
3.0.0.pre
pre
| ||
2.16.0
minor
| ||
2.15.0
minor
| ||
2.14.0
minor
| ||
2.13.0
minor
| ||
2.12.0
minor
| ||
2.11.0
minor
| ||
2.10.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.10.1
patch
| ||
2.9.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.8.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.7.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.6.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.5.1.rc1
pre
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.5.1
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.5.0.rc1
pre
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.3.3
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.3.2
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.3.1
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.6
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.5
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.2
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.1
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.0
initial
1 CVE
CVE-2023-38337
GHSA-vc79-65pr-q82v
Jul 15, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
+ 25 more Show less
1.6.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.10.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.0.rc1
2.5.1
2.5.1.rc1
2.6.0
2.7.0
2.8.0
2.9.0
Fixed in
2.10.1
References Updated Feb 16, 2024 · Source: OSV.dev |