Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:MISC:SWAGGER-CODEGEN-PI

Severity

Major

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

JSON Swagger CodeGen Parameter Injector

Release Date

2017/10/09

Update Number

2997

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: JSON Swagger CodeGen Parameter Injector


This signature detects attempts to exploit a known vulnerability in Swagger Code Generator. Successful exploitation could lead to arbitrary command injection.

References

  • BugTraq: 91419
  • CVE: CVE-2016-5641
  • URL: https://community.rapid7.com/community/infosec/blog/2016/06/23/r7-2016-06-remote-code-execution-via-swagger-parameter-injection-cve-2016-5641

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out