PT-2022-4436 · Gravitee · Gravitee Api Management

Published

2022-08-22

·

Updated

2022-08-25

·

CVE-2019-25075

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Gravitee API Management versions prior to 1.25.3
Description The issue is related to HTML injection combined with path traversal in the Email service, allowing anonymous users to read arbitrary files. This can be achieved via a /management/users/register request. The vulnerability may also enable remote attackers to conduct cross-site scripting (XSS) attacks.
Recommendations For versions prior to 1.25.3, update to version 1.25.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the /management/users/register endpoint until a patch is available. Avoid using the Email service in Gravitee API Management until the issue is resolved.

Exploit

Fix

Path traversal

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05300
CVE-2019-25075
GHSA-XC4W-28G8-VQM5

Affected Products

Gravitee Api Management