First published: Fri Apr 02 2021(Updated: )
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Okta Access Gateway | <=2020.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28113 is a command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before version 2020.9.3.
An attacker with admin access to the Okta Access Gateway UI can exploit CVE-2021-28113 to execute OS commands as a privileged system account.
CVE-2021-28113 has a severity rating of 6.7 (high).
Okta Access Gateway versions up to and including 2020.8.4 are affected by CVE-2021-28113.
To fix CVE-2021-28113, upgrade Okta Access Gateway to version 2020.9.3 or later.