Skip to main content

Swagger staggered as hacker drops dapper code execution cracker

posted onJune 24, 2016
by l33tdawg

An unpatched remote code execution hole has been publicly disclosed in the popular Swagger API framework, putting users at risk.

The client and server hole (CVE-2016-5641) exists in code generators within the REST programming tool, also know as the OpenAPI Specification.

A module for the popular Metasploit hacking suite has been crafted making exploitation of the flaw easier. Application security researcher Scott Davis says an injectable parameters in Swagger JSON or YAML files allow remote code execution across NodeJS, PHP, Ruby, and Java.

Source

Tags

Security

You May Also Like

Recent News

Wednesday, May 8th

Tuesday, May 7th

Monday, May 6th

Friday, May 3rd

Thursday, May 2nd

Wednesday, May 1st

Tuesday, April 30th