383
VMScore

CVE-2021-42357

Published: 17/01/2022 Updated: 24/01/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

When using Apache Knox SSO before 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user outside the normal request flow through a XSS or phishing campaign.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache knox

Mailing Lists

Severity: moderate Description: When using Knox SSO in affected releases, a request could be crafted to redirect a user to a malicious page due to improper URL parsing A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker This URL would need to be presented to the us ...