Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Remediation
References
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3
Related Vulnerabilities
CVE-2020-13951 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2019-10390 Vulnerability in maven package com.splunk.splunkins:splunk-devops
CVE-2023-33546 Vulnerability in maven package org.codehaus.janino:janino-parent
CVE-2022-38180 Vulnerability in maven package io.ktor:ktor-client-core