Headline
CVE-2019-25075: GitHub - gravitee-io/gravitee-api-management: Gravitee.io - OpenSource API Management
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
Gravitee.io API Management
Overview
Gravitee.io API Management is a flexible, lightweight and blazing-fast Open Source solution that helps your organization control who, when and how users access your APIs. Effortlessly manage the lifecycle of your APIs. Download API Management to document, discover and publish your APIs.
Features
Register your API : Create and register APIs in a matter of a few clicks to easily expose your secured APIs to internal and external consumers.
Configure policies using flows: Gravitee.io API Management provides over 50 pre-built policies to effectively shape traffic reaching the gateway according to your business requirements.
Developer portal: Build the portal that your developers want with a custom theme, full text search and API documentation.
Analytics dashboard: The out-of-the-box dashboards give you a 360-degree view of your API. You can also build your own dashboards from Gravitee.io or use all metrics with external tools like Grafana or Kibana.
Register applications: Users and administrators can register applications for consuming APIs with ease. Gravitee.io provides advanced dynamic client registration to effectively link API Management and Access Management.
Secured plan: Create contracts between your API consumers and APIs - building API products from your backend services.
Documentation
Community
Got questions, suggestions or feedback? Why not join us on the community forum.
Related news
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.