DOM based XSS Vulnerability in Apache Knox
CVE-2021-42357

6.1MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
17 January 2022

Summary

When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user outside the normal request flow through a XSS or phishing campaign.

Affected Version(s)

Apache Knox Apache Knox 1.x < 1.6.1

Apache Knox 0.12.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Knox would like to thank Kajetan Rostojek for this report
.