Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Remediation
References
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3
Related Vulnerabilities
CVE-2019-16564 Vulnerability in maven package com.paul8620.jenkins.plugins:pipeline-aggregator-view
CVE-2020-12827 Vulnerability in npm package mjml
CVE-2019-1003059 Vulnerability in maven package org.jvnet.hudson.plugins:ftppublisher
CVE-2020-14389 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2021-41246 Vulnerability in npm package express-openid-connect