API Management
by Gravitee
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38723 | Hig | 0.56 | 8.6 | 0.01 | Jan 3, 2023 | Gravitee API Management before 3.15.13 allows path traversal through HTML injection. | ||
| CVE-2019-25075 | Med | 0.40 | 6.1 | 0.01 | Aug 23, 2022 | HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request. |
- risk 0.56cvss 8.6epss 0.01
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
- risk 0.40cvss 6.1epss 0.01
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.