VYPR
Moderate severityNVD Advisory· Published Jan 17, 2022· Updated Aug 4, 2024

DOM based XSS Vulnerability in Apache Knox

CVE-2021-42357

Description

When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user outside the normal request flow through a XSS or phishing campaign.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.knox:gateway-service-knoxssoMaven
< 1.6.11.6.1

Affected products

2

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.