CVE-2024-22207

CVSS V2 None CVSS V3 None
Description
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option can also work around this vulnerability.
Overview
  • CVE ID
  • CVE-2024-22207
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-15T15:40:35.252Z
  • Last Modified Date
  • 2024-01-15T15:48:50.064Z
History
Created Old Value New Value Data Type Notes
2024-06-26 09:21:44 Added to TrackCVE