CRITICAL · 9.8

CVE-2019-17495

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltrat...

Vulnerability Description

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SmartbearSwagger Ui< 3.23.11
OracleBanking Apis>= 18.1, <= 18.3
OracleBanking Digital Experience>= 18.1, <= 18.3
OracleBanking Platform>= 2.4.0, <= 2.10.0
OraclePrimavera Gateway>= 16.2.0, <= 16.2.11
OracleUtilities Framework4.3.0.6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17495?

CVE-2019-17495 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltrat...

How severe is CVE-2019-17495?

CVE-2019-17495 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-17495?

Check the references section above for vendor advisories and patch information. Affected products include: Smartbear Swagger Ui, Oracle Banking Apis, Oracle Banking Digital Experience, Oracle Banking Platform, Oracle Primavera Gateway.