VulnerabilityModified
CVE-2019-25075
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
MEDIUM 6.1EPSS 0.71%
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.71% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gravitee/api management
- Source
- cve@mitre.org
References
- https://github.com/gravitee-io/gravitee-api-managementProduct, Third Party Advisory
- https://medium.com/%40maxime.escourbiac/write-up-of-path-traversal-on-gravitee-io-8835941be69f
- https://github.com/gravitee-io/gravitee-api-managementProduct, Third Party Advisory
- https://medium.com/%40maxime.escourbiac/write-up-of-path-traversal-on-gravitee-io-8835941be69f
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.