Description
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
References
ExploitThird Party AdvisoryVDB Entry
https://www.okta.com/security-advisories/cve-2021-28113
Vendor Advisory
ExploitThird Party AdvisoryVDB Entry
https://www.okta.com/security-advisories/cve-2021-28113
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
6.7 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-04-02T13:15:13.160Z
4 years agoLast modified
2024-11-21T04:59:06.290Z
1 year ago