Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Remediation
References
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3
Related Vulnerabilities
CVE-2022-34212 Vulnerability in maven package org.jenkins-ci.plugins:vmware-vrealize-orchestrator
CVE-2016-6816 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-22113 Vulnerability in maven package org.springframework.cloud:spring-cloud-netflix-zuul
CVE-2023-25765 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2021-22132 Vulnerability in maven package org.elasticsearch:elasticsearch