Description
Characters in the GET url path are not properly escaped and can be reflected in the server response.
Remediation
References
https://snyk.io/vuln/SNYK-JS-IOBROKERWEB-534971
Related Vulnerabilities
CVE-2021-40111 Vulnerability in maven package org.apache.james:james-server
CVE-2020-7686 Vulnerability in npm package rollup-plugin-dev-server
CVE-2021-23561 Vulnerability in npm package comb
CVE-2022-36898 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations
CVE-2014-3709 Vulnerability in maven package org.keycloak:keycloak-services