rswag before 2.10.1 allows remote... CVE-2023-38337

- AV AC AU C I A
发布: 2023-07-14
修订: 2023-07-27

rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息