Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Remediation
References
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3
Related Vulnerabilities
CVE-2023-22621 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2023-30543 Vulnerability in npm package @web3-react/coinbase-wallet
CVE-2019-3797 Vulnerability in maven package org.springframework.data:spring-data-jpa
CVE-2021-36774 Vulnerability in maven package org.apache.kylin:kylin-core-common