Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Remediation
References
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3
Related Vulnerabilities
CVE-2021-21297 Vulnerability in npm package @node-red/editor-api
CVE-2020-2249 Vulnerability in maven package org.jenkins-ci.plugins:tfs
CVE-2020-1936 Vulnerability in maven package org.apache.ambari:ambari-web
CVE-2023-46119 Vulnerability in npm package parse-server
CVE-2023-25753 Vulnerability in maven package org.apache.shenyu:shenyu-admin