Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
rswag 路径遍历漏洞
Vulnerability Description
rswag是rswag社区的一个将 Swagger 无缝添加到基于 Rails 的 API。 rswag 2.10.1之前版本存在安全漏洞,该漏洞源于rswag-api可以暴露一个不是项目的OpenAPI(或Swagger)规范文件的文件,导致可以通过目录遍历读取任意JSON和YAML文件。
CVSS Information
N/A
Vulnerability Type
N/A