Moderate severityNVD Advisory· Published Jan 5, 2023· Updated Mar 10, 2025
Regular expression Denial of Service in MooTools
CVE-2021-32828
Description
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the oauth2 REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.nuxeo.ecm.platform:nuxeo-platform-oauthMaven | <= 10.10 | — |
Affected products
2- Hyland/Nuxeov5Range: 11.5.109
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-x347-fc9w-w7c3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-32828ghsaADVISORY
- securitylab.github.com/advisories/GHSL-2021-072-nuxeoghsaADVISORY
- github.com/nuxeo/nuxeo/blob/master/modules/platform/nuxeo-platform-oauth/src/main/java/org/nuxeo/ecm/webengine/oauth2/OAuth2Callback.javaghsaWEB
News mentions
0No linked articles in our index yet.