Swagger-UI XSS - cbioportal.org‏‏‏‏‏‏

1,287 views
Skip to first unread message

דוד בוזגלו

unread,
Aug 25, 2022, 8:16:45 AM8/25/22
to cbiop...@googlegroups.com
Hello,

My name is David and I am a security researcher. 

In our search we found the following Swagger XSS.

Swagger UI is a really common library used to display API specifications in a nice-looking UI used by almost every company. I stumbled upon it many times when doing recon on bug bounty targets and decided to take a closer look at it in Nov 2020. On Twitch, I streamed the process of reviewing and finding bugs in the library, but I found the final payload off camera after the stream. The bug that I found was a DOM XSS, and it turned out that there were a lot of vulnerable instances.

image.png


Liked my Bug ? Buy me a coffee (or more likely a Beer X2)

Help me to continue to protect others Information .

Luke Sikina

unread,
Aug 25, 2022, 11:57:41 AM8/25/22
to cBioPortal for Cancer Genomics Discussion Group
Hi David,

Thanks for the repro! We have a patch for this that will go live next week.

Reply all
Reply to author
Forward
0 new messages