ZeroHour

CVE-2021-28113

PoC
CVSS 3.1
6.7 medium
EPSS
22%p98
Published
()
Modified
Description

A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.

Vendors
okta
Products
access gateway
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.