High severity8.6NVD Advisory· Published Jan 3, 2023· Updated Jun 17, 2026
CVE-2022-38723
CVE-2022-38723
Description
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.gravitee.apim:gravitee-api-managementMaven | < 3.15.13 | 3.15.13 |
Affected products
3cpe:2.3:a:gravitee:api_management:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gravitee:api_management:*:*:*:*:*:*:*:*range: <3.15.3
- (no CPE)
Patches
Vulnerability mechanics
References
5- community.gravitee.io/t/whats-new-in-access-management-3-15-lts/164nvdRelease NotesVendor AdvisoryWEB
- gist.github.com/garatc/d86cdb1fa2e35a7ee719d9a0de0b5ca3nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-vp62-m958-qj8cghsaADVISORY
- github.com/advisories/GHSA-xc4w-28g8-vqm5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-38723ghsaADVISORY
News mentions
0No linked articles in our index yet.