Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Remediation
References
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3
Related Vulnerabilities
CVE-2023-31103 Vulnerability in maven package org.apache.inlong:manager-test
CVE-2020-9488 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2022-45397 Vulnerability in maven package org.jenkins-ci.plugins:osf-builder-suite-xml-linter
CVE-2021-41184 Vulnerability in maven package org.webjars:jquery-ui
CVE-2022-24437 Vulnerability in npm package git-pull-or-clone