Recently, a wide range of popular language development applications such as Java, PHP, Nodejs and Ruby have been discovered, the vulnerability exists in Openapi (Swagger Code Generator), a parameter injection vulnerability, Any application that integrates OPENAPI will be affected. An attacker could exploit this vulnerability to embed malicious code in a swagger JSON file for remote execution. It is worth noting that the vulnerability had been disclosed in April 2016 as early as the details and fixes, but it did not seem to be the attention of swagger defenders, because they have never responded to this matter. For security reasons, relevant developers and technicians should step up the deployment of vulnerability remediation to eliminate potential threats to the vulnerability as early as possible. Learn more about the software development channel of Xian JI network: http://www.xianjichina.com/news/list_78
OpenAPI (Swagger Code Generator) Injection Vulnerability