Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Remediation
References
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3
Related Vulnerabilities
CVE-2021-35513 Vulnerability in npm package mermaid
CVE-2018-1000014 Vulnerability in maven package org.jenkins-ci.plugins:translation
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2018-6342 Vulnerability in npm package react-dev-utils
CVE-2020-15839 Vulnerability in maven package com.liferay.portal:release.dxp.bom