<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>API_2023_API9 on ZAP</title>
    <link>/alerttags/api_2023_api9/</link>
    <description>Recent content in API_2023_API9 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/api_2023_api9/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Exposed Secrets in Swagger/OpenAPI Path</title>
      <link>/docs/alerts/100043-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100043-2/</guid>
      <description>&lt;p&gt;Swagger UI endpoint exposes sensitive secrets such as client secrets, API keys, or OAuth tokens. These secrets may be accessible in the HTML source and should not be exposed publicly, as this can lead to compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerable Swagger UI Version Detected</title>
      <link>/docs/alerts/100043-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100043-1/</guid>
      <description>&lt;p&gt;This Swagger UI version is known to contain vulnerabilities. Exploitation may allow unauthorized access, XSS, or token theft.&lt;/p&gt;&#xA;&lt;p&gt;Affected versions:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Swagger UI v2 &amp;lt; 2.2.10&lt;/li&gt;&#xA;&lt;li&gt;Swagger UI v3 &amp;lt; 3.24.3&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
  </channel>
</rss>
