Description
Characters in the GET url path are not properly escaped and can be reflected in the server response.
Remediation
References
https://snyk.io/vuln/SNYK-JS-IOBROKERWEB-534971
Related Vulnerabilities
CVE-2017-7657 Vulnerability in maven package org.eclipse.jetty:jetty-client
CVE-2022-35204 Vulnerability in maven package org.webjars.npm:vite
CVE-2020-12265 Vulnerability in maven package org.webjars:decompress
CVE-2023-26487 Vulnerability in maven package org.webjars.npm:vega
CVE-2019-16728 Vulnerability in maven package org.webjars.npm:dompurify