Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
References
Link | Resource |
---|---|
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164 | Release Notes Vendor Advisory |
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3 | Third Party Advisory |
https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164 | Release Notes Vendor Advisory |
https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3 | Third Party Advisory |
Configurations
History
21 Nov 2024, 07:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164 - Release Notes, Vendor Advisory | |
References | () https://gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3 - Third Party Advisory |
Information
Published : 2023-01-03 22:15
Updated : 2024-11-21 07:16
NVD link : CVE-2022-38723
Mitre link : CVE-2022-38723
CVE.ORG link : CVE-2022-38723
JSON object : View
Products Affected
gravitee
- api_management