CVE-2021-28113: OS Command Injection
Published Apr 2, 2021
·Updated
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
Affected Software
1 affected component
Okta Access Gateway<=2020.8.4
Event History
Apr 2, 2021
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2021-28113?
CVE-2021-28113 is a command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before version 2020.9.3.
2
How can an attacker exploit CVE-2021-28113?
An attacker with admin access to the Okta Access Gateway UI can exploit CVE-2021-28113 to execute OS commands as a privileged system account.
3
What is the severity of CVE-2021-28113?
CVE-2021-28113 has a severity rating of 6.7 (high).
4
Which software versions are affected by CVE-2021-28113?
Okta Access Gateway versions up to and including 2020.8.4 are affected by CVE-2021-28113.
5
How can I fix CVE-2021-28113?
To fix CVE-2021-28113, upgrade Okta Access Gateway to version 2020.9.3 or later.