CVE-2021-28113 - CERT CVE
ID CVE-2021-28113
Sažetak A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
Reference
CVSS
Base: 8.7
Impact: 9.5
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE PARTIAL
CVSS vektor AV:N/AC:L/Au:S/C:C/I:C/A:P
Zadnje važnije ažuriranje 27-05-2022 - 16:47
Objavljeno 02-04-2021 - 15:15