Command Injection Vulnerability in Okta Access Gateway
CVE-2021-28113
6.7MEDIUM
What is CVE-2021-28113?
A command injection vulnerability exists in the cookieDomain and relayDomain parameters of Okta Access Gateway versions prior to 2020.9.3. This flaw enables authenticated attackers with administrative access to the Okta Access Gateway user interface to execute arbitrary operating system commands, potentially compromising the integrity and security of the targeted systems. Immediate remediation is necessary to mitigate risks associated with unauthorized command execution.