Description
Characters in the GET url path are not properly escaped and can be reflected in the server response.
Remediation
References
https://snyk.io/vuln/SNYK-JS-IOBROKERWEB-534971
Related Vulnerabilities
CVE-2022-43433 Vulnerability in maven package io.jenkins.plugins:screenrecorder
CVE-2022-39944 Vulnerability in maven package org.apache.linkis:linkis-engineplugin-jdbc
CVE-2021-25948 Vulnerability in npm package expand-hash
CVE-2022-23708 Vulnerability in maven package org.elasticsearch:elasticsearch