CVE-2021-23888: McAfee ePO unvalidated URL redirect vulnerability
Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-23888?
CVE-2021-23888 is an unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10.
How does CVE-2021-23888 affect McAfee ePolicy Orchestrator?
CVE-2021-23888 could cause an authenticated ePO user to load an untrusted site in an ePO iframe, which could steal information from the authenticated user.
What is the severity of CVE-2021-23888?
CVE-2021-23888 has a severity of 6.3 (Medium).
How can I fix CVE-2021-23888?
To fix CVE-2021-23888, users should update McAfee ePolicy Orchestrator to version 5.10 Update 10 or later.
Where can I find more information about CVE-2021-23888?
More information about CVE-2021-23888 can be found at the following reference link: https://kc.mcafee.com/corporate/index?page=content&id=SB10352