VYPR

Knox

by Apache

Source repositories

CVEs (2)

  • CVE-2021-42357MedJan 17, 2022
    risk 0.40cvss 6.1epss 0.03

    When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This…

  • CVE-2017-5646MedMay 26, 2017
    risk 0.37cvss 6.8epss 0.01

    For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit…