Gravitee API Management contains Path Traversal
High severity
GitHub Reviewed
Published
Jan 4, 2023
to the GitHub Advisory Database
•
Updated Jan 23, 2023
Package
Affected versions
< 3.15.13
Patched versions
3.15.13
Description
Published by the National Vulnerability Database
Jan 3, 2023
Published to the GitHub Advisory Database
Jan 4, 2023
Reviewed
Jan 6, 2023
Last updated
Jan 23, 2023
This CVE addresses the partial fix for CVE-2019-25075
Gravitee API Management before 3.15.13 allows path traversal through HTML injection. A certain HTML injection combined with path traversal in the Email service in Gravitee API Management before 3.15.13 allows anonymous users to read arbitrary files via a /management/users/register request.
A patch was published in 2019 for this vulnerability but did not appear to have solved the issue. Version 3.15.13 did remove the flaw.
References