First published: Mon Nov 08 2021(Updated: )
A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OPNsense OPNsense | <=19.7.0 | |
OPNsense OPNsense | >=21.7.0<21.7.4 | |
<=19.7.0 | ||
>=21.7.0<21.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-42770 is medium.
CVE-2021-42770 affects OPNsense versions before 21.7.4.
The CWE category of CVE-2021-42770 is CWE-79 (Cross-Site Scripting).
To fix CVE-2021-42770, you need to update OPNsense to version 21.7.4 or later.
You can find more information about CVE-2021-42770 on the following references: [Orange CERT](https://cert.orange.com), [GitHub Security Advisory](https://github.com/orangecertcc/security-research/security/advisories/GHSA-r32j-xgg3-w2rw), [OPNsense 21.7.4 Release Announcement](https://opnsense.org/opnsense-21-7-4-released/).