CVE-2021-32828: GHSL-2021-072: Reflected Cross-Site Scripting (XSS) leading to Remote Code Execution (RCE) in Nuxeo - CVE-2021-32828
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the oauth2 REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.
Other sources
The oauth2 REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.
— GitHub Security Lab
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32828?
CVE-2021-32828 is classified as a high severity vulnerability due to its potential for exploitation resulting in Remote Code Execution.
How do I fix CVE-2021-32828?
To fix CVE-2021-32828, upgrade to a version of the Nuxeo Platform that is higher than 11.5.109.
What type of vulnerability is CVE-2021-32828?
CVE-2021-32828 is a Reflected Cross-Site Scripting (XSS) vulnerability that can lead to Remote Code Execution.
Which versions of Nuxeo are affected by CVE-2021-32828?
CVE-2021-32828 affects Nuxeo Platform version 11.5.109 and prior.
Can CVE-2021-32828 be exploited remotely?
Yes, CVE-2021-32828 can be exploited remotely, allowing attackers to execute arbitrary code.